AI Act Requirements
Follow topic LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this topic. Contains: the overview, key law text, case law, enforcement and guidance for this topic. Everything links back to its source on overview.legal — legal information, not advice.The content specifically addresses 'Compliance with the requirements' from the AI Act, which warrants a dedicated topic for AI Act-specific requirements that goes beyond general compliance and risk assessment topics.
Overview
9 sources · Jul 15, 2026Legal Framework
The AI Act establishes a layered compliance architecture for high-risk AI systems, anchored by three core obligations. Article 9 requires providers to implement a continuous, iterative risk management system throughout the entire lifecycle of an AI system. This is not a one-time assessment but an ongoing process that must identify and mitigate known and reasonably foreseeable risks, including those arising from the system's intended use and reasonably foreseeable misuse. Residual risks that remain after mitigation must be reduced to acceptable levels, and the system can only be placed on the market if remaining risks are deemed acceptable.
Article 11 imposes detailed technical documentation requirements. Providers must compile and maintain technical documentation that demonstrates conformity with the AI Act's requirements before placing a high-risk system on the market. This documentation must be drawn up before the system enters the market and must be kept up to date throughout its lifecycle. The documentation serves as the evidentiary backbone for conformity assessment and must be made available to national competent authorities upon request.
Article 72 complements these ex-ante obligations with a post-market monitoring regime. Providers must actively and systematically monitor the performance and compliance of high-risk AI systems after they have been placed on the market. A written post-market monitoring plan must be established, proportionate to the nature and risks of the AI system. This plan functions as a structured mechanism for gathering, analyzing, and acting on data about system performance in real-world conditions.
Key Developments
The transparency obligations under the AI Act take effect on August 2, 2026, with the Dutch Data Protection Authority (Autoriteit Persoonsgegevens) actively encouraging organizations to sign a practical code of conduct in advance. This signals that supervisory authorities are already positioning themselves to enforce AI Act requirements, particularly where AI systems process personal data and trigger overlapping GDPR obligations. The interplay between AI Act documentation duties and GDPR accountability principles — including record-keeping under Article 30 GDPR and data protection impact assessments — creates a compounded compliance burden that regulators will assess holistically.
Practical Guidance
- Establish a lifecycle-integrated risk management process under Article 9 that documents risk identification, mitigation measures, and residual risk evaluation at each development and deployment stage — not merely at launch.
- Prepare technical documentation before market placement that maps directly to each Article 11 annex requirement, ensuring it is sufficiently detailed for authorities to verify conformity without access to source code or proprietary models.
- Design a post-market monitoring plan under Article 72 that defines specific performance metrics, incident reporting triggers, and feedback loops to update the risk management system when real-world performance diverges from pre-market expectations.
- Align AI Act and GDPR documentation streams to avoid duplication and contradictions — technical documentation under Article 11 should cross-reference DPIA outcomes and records of processing activities where the AI system processes personal data.
- Anticipate the August 2026 transparency deadline by auditing current AI systems now against the forthcoming transparency requirements and engaging with sectoral codes of conduct that supervisory authorities are actively promoting.