Skip to content
Topic Developing

AI Act Requirements

LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this topic. Contains: the overview, key law text, case law, enforcement and guidance for this topic. Everything links back to its source on overview.legal — legal information, not advice.

The content specifically addresses 'Compliance with the requirements' from the AI Act, which warrants a dedicated topic for AI Act-specific requirements that goes beyond general compliance and risk assessment topics.

24 linked items 22 Laws2 News

Overview

9 sources · Jul 15, 2026

Legal Framework

The AI Act establishes a layered compliance architecture for high-risk AI systems, anchored by three core obligations. Article 9 requires providers to implement a continuous, iterative risk management system throughout the entire lifecycle of an AI system. This is not a one-time assessment but an ongoing process that must identify and mitigate known and reasonably foreseeable risks, including those arising from the system's intended use and reasonably foreseeable misuse. Residual risks that remain after mitigation must be reduced to acceptable levels, and the system can only be placed on the market if remaining risks are deemed acceptable.

Article 11 imposes detailed technical documentation requirements. Providers must compile and maintain technical documentation that demonstrates conformity with the AI Act's requirements before placing a high-risk system on the market. This documentation must be drawn up before the system enters the market and must be kept up to date throughout its lifecycle. The documentation serves as the evidentiary backbone for conformity assessment and must be made available to national competent authorities upon request.

Article 72 complements these ex-ante obligations with a post-market monitoring regime. Providers must actively and systematically monitor the performance and compliance of high-risk AI systems after they have been placed on the market. A written post-market monitoring plan must be established, proportionate to the nature and risks of the AI system. This plan functions as a structured mechanism for gathering, analyzing, and acting on data about system performance in real-world conditions.

Key Developments

The transparency obligations under the AI Act take effect on August 2, 2026, with the Dutch Data Protection Authority (Autoriteit Persoonsgegevens) actively encouraging organizations to sign a practical code of conduct in advance. This signals that supervisory authorities are already positioning themselves to enforce AI Act requirements, particularly where AI systems process personal data and trigger overlapping GDPR obligations. The interplay between AI Act documentation duties and GDPR accountability principles — including record-keeping under Article 30 GDPR and data protection impact assessments — creates a compounded compliance burden that regulators will assess holistically.

Practical Guidance

  • Establish a lifecycle-integrated risk management process under Article 9 that documents risk identification, mitigation measures, and residual risk evaluation at each development and deployment stage — not merely at launch.
  • Prepare technical documentation before market placement that maps directly to each Article 11 annex requirement, ensuring it is sufficiently detailed for authorities to verify conformity without access to source code or proprietary models.
  • Design a post-market monitoring plan under Article 72 that defines specific performance metrics, incident reporting triggers, and feedback loops to update the risk management system when real-world performance diverges from pre-market expectations.
  • Align AI Act and GDPR documentation streams to avoid duplication and contradictions — technical documentation under Article 11 should cross-reference DPIA outcomes and records of processing activities where the AI system processes personal data.
  • Anticipate the August 2026 transparency deadline by auditing current AI systems now against the forthcoming transparency requirements and engaging with sectoral codes of conduct that supervisory authorities are actively promoting.
Everything on this topic, by type links go to the exact provision / paragraph / section
Laws 22
Art. 3(12) ‘intended purpose’ means the use for which an AI system is intended by the provider, including the specific context and conditions of use, as specifie… AI Act Art. 3(25) ‘post-market monitoring system’ means all activities carried out by providers of AI systems to collect and review experience gained from the use of AI… AI Act Art. 5(2)(cont)(1) In addition, the use of ‘real-time’ remote biometric identification systems in publicly accessible spaces for the purposes of law enforcement for any … AI Act Art. 8(1) High-risk AI systems shall comply with the requirements laid down in this Section, taking into account their intended purpose as well as the generally… AI Act rec 101 Recital 101 — General-purpose AI model provider transparency obligations AI Act Jun 2024 art 27 Fundamental rights impact assessment for high-risk AI systems AI Act Jun 2024 rec 71 Recital 71 — high-risk AI technical documentation and logs AI Act Jun 2024 rec 65 Recital 65 — high-risk AI risk management system AI Act Jun 2024 rec 155 Recital 155 — high-risk AI post-market monitoring systems AI Act Jun 2024 rec 132 Recital 132 — transparency obligations for deceptive AI AI Act Jun 2024 art 50 Transparency obligations for providers and deployers of certain AI systems AI Act Jun 2024 art 72 Post-market monitoring by providers and post-market monitoring plan for high-risk AI systems AI Act Jun 2024 rec 96 Recital 96 — fundamental rights impact assessment deployers AI Act Jun 2024 art 9 Risk management system AI Act Jun 2024 art 11 Technical documentation AI Act Jun 2024 rec 174 Recital 174 — Commission review and evaluation obligations AI Act Jun 2024 rec 173 Recital 173 — Commission delegated powers to adapt AI rules AI Act Jun 2024 rec 81 Recital 81 — provider quality management system AI Act Jun 2024 rec 66 Recital 66 — risk management requirements for high-risk AI AI Act Jun 2024 rec 114 Recital 114 — systemic risk AI model obligations AI Act Jun 2024 rec 135 Recital 135 — Union level codes for AI content labelling AI Act Jun 2024 rec 137 Recital 137 — transparency compliance not implying lawfulness AI Act Jun 2024 rec 109 Recital 109 — proportionate compliance for general-purpose AI providers AI Act Jun 2024 rec 26 Recital 26 — risk-based approach to AI regulation AI Act Jun 2024 Show 2 more →
News 2
Autoriteit Persoonsgegevens De FRIA voor AI-systemen komt eraan: bereid u voor Autoriteit Persoonsgegevens Aug 2026 NL Autoriteit Persoonsgegevens AI transparency requirements apply from August 2: AP advises signing code of practice Autoriteit Persoonsgegevens Jul 2026