EU AI Act · Arts. 8-21, 43, 47-49, 72-73
High-risk provider obligations (risk management, data governance, technical docs, logging, oversight, accuracy, QMS, conformity assessment, CE marking, registration, post-market monitoring)
Build toward the full conformity package now: Arts. 9-15 systems and documentation, Art. 17 quality management system, Arts. 18-20 record-keeping and corrective actions, Art. 43 conformity assessment, Arts. 47-48 declaration of conformity and CE marking, Art. 49 EU database registration, and Arts. 72-73 post-market monitoring and serious-incident reporting.
By the Shieldra Compliance Team · Last updated 2026-07-29
What do you actually have to do?
Build toward the full conformity package now: Arts. 9-15 systems and documentation, Art. 17 quality management system, Arts. 18-20 record-keeping and corrective actions, Art. 43 conformity assessment, Arts. 47-48 declaration of conformity and CE marking, Art. 49 EU database registration, and Arts. 72-73 post-market monitoring and serious-incident reporting.
Statutory basis: Arts. 8-21, 43, 47-49, 72-73 — https://artificialintelligenceact.eu/article/8/
When does it apply?
- 2028-08-02 — deferred to 2 August 2028 (Annex I, Digital Omnibus)
- 2027-12-02 — deferred to 2 December 2027 (Annex III, Digital Omnibus)
Does ISO 42001 or NIST AI RMF cover this duty?
Requirement-level mappings from Shieldra's crosswalk pack (v2026.07.30). Partial mappings contribute evidence but deliberately do not count as coverage.
| Mapped requirement | Strength | Why (and what’s missing) |
|---|
| ISO/IEC 42001 4.4 | Partial | An operating AIMS supplies much of the Art. 17 quality-management-system skeleton, but the Act prescribes elements (conformity procedures, post-market plan) the standard does not. |
| ISO/IEC 42001 6.1.2 | Partial | The ISO risk assessment process is the backbone of the Art. 9 risk-management system, which is one component of the conformity bundle. |
| ISO/IEC 42001 A.6 | Partial | A.6 life-cycle controls produce technical documentation and verification evidence toward Arts. 11 and 15, a fraction of the full package. |
| ISO/IEC 42001 A.7 | Partial | A.7 data management maps to the Art. 10 data-governance duty but not to the specific training/validation/test data criteria the Act prescribes. |
| NIST AI RMF MAP-1.1 | Partial | Documented intended purpose, context, assumptions, and limitations supplies core Annex IV technical-documentation content, one piece of the package. |
| NIST AI RMF MAP-3.5 | Partial | Defined and assessed human-oversight processes map directly to Art. 14, one element of the conformity bundle. |
| NIST AI RMF MEASURE-2.3 | Partial | Performance measurement under deployment-like conditions evidences Art. 15 accuracy and robustness, without the conformity-assessment wrapper. |
| NIST AI RMF MANAGE-4.1 | Partial | A post-deployment monitoring plan with incident response is the substance of Art. 72 post-market monitoring, one piece of the bundle. |
Disclaimer
Compliance guidance, not legal advice. Confirm obligations with counsel. Pack verified 2026-07-29.
Frequently asked questions
What does "High-risk provider obligations (risk management, data governance, technical docs, logging, oversight, accuracy, QMS, conformity assessment, CE marking, registration, post-market monitoring)" require?
Build toward the full conformity package now: Arts. 9-15 systems and documentation, Art. 17 quality management system, Arts. 18-20 record-keeping and corrective actions, Art. 43 conformity assessment, Arts. 47-48 declaration of conformity and CE marking, Art. 49 EU database registration, and Arts. 72-73 post-market monitoring and serious-incident reporting.
When does this obligation apply?
deferred to 2 August 2028 (Annex I, Digital Omnibus). deferred to 2 December 2027 (Annex III, Digital Omnibus)
Who does this obligation apply to?
The provider role under the EU AI Act. Statutory basis: Arts. 8-21, 43, 47-49, 72-73.