EU AI Act · Arts. 8-21, 43, 47-49, 72-73

High-risk provider obligations (risk management, data governance, technical docs, logging, oversight, accuracy, QMS, conformity assessment, CE marking, registration, post-market monitoring)

Build toward the full conformity package now: Arts. 9-15 systems and documentation, Art. 17 quality management system, Arts. 18-20 record-keeping and corrective actions, Art. 43 conformity assessment, Arts. 47-48 declaration of conformity and CE marking, Art. 49 EU database registration, and Arts. 72-73 post-market monitoring and serious-incident reporting.

What do you actually have to do?

Build toward the full conformity package now: Arts. 9-15 systems and documentation, Art. 17 quality management system, Arts. 18-20 record-keeping and corrective actions, Art. 43 conformity assessment, Arts. 47-48 declaration of conformity and CE marking, Art. 49 EU database registration, and Arts. 72-73 post-market monitoring and serious-incident reporting.

Statutory basis: Arts. 8-21, 43, 47-49, 72-73 — https://artificialintelligenceact.eu/article/8/

Who does this apply to?

  • Provider

When does it apply?

  • 2028-08-02 — 2 August 2028 (Annex I, deferred by the Digital Omnibus)
  • 2027-12-02 — 2 December 2027 (Annex III, deferred by the Digital Omnibus)

Does ISO 42001 or NIST AI RMF cover this duty?

Requirement-level mappings from Shieldra's crosswalk pack (v2026.07.30). Partial mappings contribute evidence but deliberately do not count as coverage.

Mapped requirementStrengthWhy (and what’s missing)
ISO/IEC 42001 4.4PartialAn operating AIMS supplies much of the Art. 17 quality-management-system skeleton, but the Act prescribes elements (conformity procedures, post-market plan) the standard does not.
ISO/IEC 42001 6.1.2PartialThe ISO risk assessment process is the backbone of the Art. 9 risk-management system, which is one component of the conformity bundle.
ISO/IEC 42001 A.6PartialA.6 life-cycle controls produce technical documentation and verification evidence toward Arts. 11 and 15, a fraction of the full package.
ISO/IEC 42001 A.7PartialA.7 data management maps to the Art. 10 data-governance duty but not to the specific training/validation/test data criteria the Act prescribes.
NIST AI RMF MAP-1.1PartialDocumented intended purpose, context, assumptions, and limitations supplies core Annex IV technical-documentation content, one piece of the package.
NIST AI RMF MAP-3.5PartialDefined and assessed human-oversight processes map directly to Art. 14, one element of the conformity bundle.
NIST AI RMF MEASURE-2.3PartialPerformance measurement under deployment-like conditions evidences Art. 15 accuracy and robustness, without the conformity-assessment wrapper.
NIST AI RMF MANAGE-4.1PartialA post-deployment monitoring plan with incident response is the substance of Art. 72 post-market monitoring, one piece of the bundle.

Disclaimer

Compliance guidance, not legal advice. Confirm obligations with counsel. Pack verified 2026-09-16.

Frequently asked questions

What does "High-risk provider obligations (risk management, data governance, technical docs, logging, oversight, accuracy, QMS, conformity assessment, CE marking, registration, post-market monitoring)" require?

Build toward the full conformity package now: Arts. 9-15 systems and documentation, Art. 17 quality management system, Arts. 18-20 record-keeping and corrective actions, Art. 43 conformity assessment, Arts. 47-48 declaration of conformity and CE marking, Art. 49 EU database registration, and Arts. 72-73 post-market monitoring and serious-incident reporting.

When does this obligation apply?

2 August 2028 (Annex I, deferred by the Digital Omnibus). 2 December 2027 (Annex III, deferred by the Digital Omnibus)

Who does this obligation apply to?

The provider role under the EU AI Act. Statutory basis: Arts. 8-21, 43, 47-49, 72-73.