# AI Act Requirements — legal context bundle

> Curated from overview.legal on 2026-08-22. Canonical page: https://overview.legal/topics/ai-act-requirements
> Sources are cited per item. Verify against the official texts before relying on them.

The content specifically addresses 'Compliance with the requirements' from the AI Act, which warrants a dedicated topic for AI Act-specific requirements that goes beyond general compliance and risk assessment topics.

## Overview

## Legal Framework

The AI Act establishes a layered compliance architecture for high-risk AI systems, anchored by three core obligations. Article 9 requires providers to implement a continuous, iterative risk management system throughout the entire lifecycle of an AI system. This is not a one-time assessment but an ongoing process that must identify and mitigate known and reasonably foreseeable risks, including those arising from the system's intended use and reasonably foreseeable misuse. Residual risks that remain after mitigation must be reduced to acceptable levels, and the system can only be placed on the market if remaining risks are deemed acceptable.

Article 11 imposes detailed technical documentation requirements. Providers must compile and maintain technical documentation that demonstrates conformity with the AI Act's requirements before placing a high-risk system on the market. This documentation must be drawn up before the system enters the market and must be kept up to date throughout its lifecycle. The documentation serves as the evidentiary backbone for conformity assessment and must be made available to national competent authorities upon request.

Article 72 complements these ex-ante obligations with a post-market monitoring regime. Providers must actively and systematically monitor the performance and compliance of high-risk AI systems after they have been placed on the market. A written post-market monitoring plan must be established, proportionate to the nature and risks of the AI system. This plan functions as a structured mechanism for gathering, analyzing, and acting on data about system performance in real-world conditions.

## Key Developments

The transparency obligations under the AI Act take effect on August 2, 2026, with the Dutch Data Protection Authority (Autoriteit Persoonsgegevens) actively encouraging organizations to sign a practical code of conduct in advance. This signals that supervisory authorities are already positioning themselves to enforce AI Act requirements, particularly where AI systems process personal data and trigger overlapping GDPR obligations. The interplay between AI Act documentation duties and GDPR accountability principles — including record-keeping under Article 30 GDPR and data protection impact assessments — creates a compounded compliance burden that regulators will assess holistically.

## Practical Guidance

- **Establish a lifecycle-integrated risk management process** under Article 9 that documents risk identification, mitigation measures, and residual risk evaluation at each development and deployment stage — not merely at launch.
- **Prepare technical documentation before market placement** that maps directly to each Article 11 annex requirement, ensuring it is sufficiently detailed for authorities to verify conformity without access to source code or proprietary models.
- **Design a post-market monitoring plan** under Article 72 that defines specific performance metrics, incident reporting triggers, and feedback loops to update the risk management system when real-world performance diverges from pre-market expectations.
- **Align AI Act and GDPR documentation streams** to avoid duplication and contradictions — technical documentation under Article 11 should cross-reference DPIA outcomes and records of processing activities where the AI system processes personal data.
- **Anticipate the August 2026 transparency deadline** by auditing current AI systems now against the forthcoming transparency requirements and engaging with sectoral codes of conduct that supervisory authorities are actively promoting.

## Legislation (full text of key provisions)

### Fundamental rights impact assessment for high-risk AI systems

*Source: AI Act, aiact-art-27-en, 2024-06-12 — https://overview.legal/posts/92424*

### Transparency obligations for providers and deployers of certain AI systems

*Source: AI Act, aiact-art-50-en, 2024-06-12 — https://overview.legal/posts/92746*

### Post-market monitoring by providers and post-market monitoring plan for high-risk AI systems

*Source: AI Act, aiact-art-72-en, 2024-06-12 — https://overview.legal/posts/93175*

### Risk management system

*Source: AI Act, aiact-art-9-en, 2024-06-12 — https://overview.legal/posts/92094*

### Technical documentation

*Source: AI Act, aiact-art-11-en, 2024-06-12 — https://overview.legal/posts/92155*

### Recital 101 — General-purpose AI model provider transparency obligations

*Source: AI Act, aiact-rec-101-en, 2024-06-12 — https://overview.legal/posts/93884*

Providers of general-purpose AI models have a particular role and responsibility along the AI value chain, as the models they provide may form the basis for a range of downstream systems, often provided by downstream providers that necessitate a good understanding of the models and their capabilities, both to enable the integration of such models into their products, and to fulfil their obligations under this or other regulations. Therefore, proportionate transparency measures should be laid down, including the drawing up and keeping up to date of documentation, and the provision of information on the general-purpose AI model for its usage by the downstream providers. Technical documentation should be prepared and kept up to date by the general-purpose AI model provider for the purpose of making it available, upon request, to the AI Office and the national competent authorities. The minimal set of elements to be included in such documentation should be set out in specific annexes to this Regulation. The Commission should be empowered to amend those annexes by means of delegated acts in light of evolving technological developments.

### Recital 71 — high-risk AI technical documentation and logs

*Source: AI Act, aiact-rec-71-en, 2024-06-12 — https://overview.legal/posts/93824*

Having comprehensible information on how high-risk AI systems have been developed and how they perform throughout their lifetime is essential to enable traceability of those systems, verify compliance with the requirements under this Regulation, as well as monitoring of their operations and post market monitoring. This requires keeping records and the availability of technical documentation, containing information which is necessary to assess the compliance of the AI system with the relevant requirements and facilitate post market monitoring. Such information should include the general characteristics, capabilities and limitations of the system, algorithms, data, training, testing and validation processes used as well as documentation on the relevant risk-management system and drawn in a clear and comprehensive form. The technical documentation should be kept up to date, appropriately throughout the lifetime of the AI system. Furthermore, high-risk AI systems should technically allow for the automatic recording of events, by means of logs, over the duration of the lifetime of the system.

### Recital 65 — high-risk AI risk management system

*Source: AI Act, aiact-rec-65-en, 2024-06-12 — https://overview.legal/posts/93812*

The risk-management system should consist of a continuous, iterative process that is planned and run throughout the entire lifecycle of a high-risk AI system. That process should be aimed at identifying and mitigating the relevant risks of AI systems on health, safety and fundamental rights. The risk-management system should be regularly reviewed and updated to ensure its continuing effectiveness, as well as justification and documentation of any significant decisions and actions taken subject to this Regulation. This process should ensure that the provider identifies risks or adverse impacts and implements mitigation measures for the known and reasonably foreseeable risks of AI systems to the health, safety and fundamental rights in light of their intended purpose and reasonably foreseeable misuse, including the possible risks arising from the interaction between the AI system and the environment within which it operates. The risk-management system should adopt the most appropriate risk-management measures in light of the state of the art in AI. When identifying the most appropriate risk-management measures, the provider should document and explain the choices made and, when relevant, involve experts and external stakeholders. In identifying the reasonably foreseeable misuse of high-risk AI systems, the provider should cover uses of AI systems which, while not directly covered by the intended purpose and provided for in the instruction for use may nevertheless be reasonably expected to result from readily predictable human behaviour in the context of the specific characteristics and use of a particular AI system. Any known or foreseeable circumstances related to the use of the high-risk AI system in accordance with its intended purpose or under conditions of reasonably foreseeable misuse, which may lead to risks to the health and safety or fundamental rights should be included in the instructions for use that are provided by the provider. This is to ensure that the deployer is aware and takes them into account when using the high-risk AI system. Identifying and implementing risk mitigation measures for foreseeable misuse under this Regulation should not require specific additional training for the high-risk AI system by the provider to address foreseeable misuse. The providers however are encouraged to consider such additional training measures to mitigate reasonable foreseeable misuses as necessary and appropriate.

### Recital 155 — high-risk AI post-market monitoring systems

*Source: AI Act, aiact-rec-155-en, 2024-06-12 — https://overview.legal/posts/93992*

In order to ensure that providers of high-risk AI systems can take into account the experience on the use of high-risk AI systems for improving their systems and the design and development process or can take any possible corrective action in a timely manner, all providers should have a post-market monitoring system in place. Where relevant, post-market monitoring should include an analysis of the interaction with other AI systems including other devices and software. Post-market monitoring should not cover sensitive operational data of deployers which are law enforcement authorities. This system is also key to ensure that the possible risks emerging from AI systems which continue to ‘learn’ after being placed on the market or put into service can be more efficiently and timely addressed. In this context, providers should also be required to have a system in place to report to the relevant authorities any serious incidents resulting from the use of their AI systems, meaning incident or malfunctioning leading to death or serious damage to health, serious and irreversible disruption of the management and operation of critical infrastructure, infringements of obligations under Union law intended to protect fundamental rights or serious damage to property or the environment.

### Recital 132 — transparency obligations for deceptive AI

*Source: AI Act, aiact-rec-132-en, 2024-06-12 — https://overview.legal/posts/93946*

Certain AI systems intended to interact with natural persons or to generate content may pose specific risks of impersonation or deception irrespective of whether they qualify as high-risk or not. In certain circumstances, the use of these systems should therefore be subject to specific transparency obligations without prejudice to the requirements and obligations for high-risk AI systems and subject to targeted exceptions to take into account the special need of law enforcement. In particular, natural persons should be notified that they are interacting with an AI system, unless this is obvious from the point of view of a natural person who is reasonably well-informed, observant and circumspect taking into account the circumstances and the context of use. When implementing that obligation, the characteristics of natural persons belonging to vulnerable groups due to their age or disability should be taken into account to the extent the AI system is intended to interact with those groups as well. Moreover, natural persons should be notified when they are exposed to AI systems that, by processing their biometric data, can identify or infer the emotions or intentions of those persons or assign them to specific categories. Such specific categories can relate to aspects such as sex, age, hair colour, eye colour, tattoos, personal traits, ethnic origin, personal preferences and interests. Such information and notifications should be provided in accessible formats for persons with disabilities.

## Recent developments

### De FRIA voor AI-systemen komt eraan: bereid u voor

*Source: Autoriteit Persoonsgegevens, 2026-08-17 — https://overview.legal/posts/291285 — original: https://autoriteitpersoonsgegevens.nl/actueel/de-fria-voor-ai-systemen-komt-eraan-bereid-u-voor*

Bent u een overheidsorganisatie of een private organisatie die publieke diensten levert? En bent u van plan een AI-systeem met een hoog risico te gaan gebruiken? Of gaat u als publieke of private organisatie een beoordelingssysteem voor financiële risico’s gebruiken? Dan moet u vanaf december 2027 vooraf beoordelen welke gevolgen dit AI-systeem kan hebben voor de grondrechten van mensen. Zo’n beoordeling heet een ‘fundamental rights impact assessment’ (FRIA), oftewel een ‘grondrechteneffectbeoor

### Transparantie-eisen AI gelden vanaf 2 augustus: AP adviseert praktijkcode te ondertekenen

*Source: Autoriteit Persoonsgegevens, 2026-07-09 — https://overview.legal/posts/83468 — original: https://autoriteitpersoonsgegevens.nl/actueel/transparantie-eisen-ai-gelden-vanaf-2-augustus-ap-adviseert-praktijkcode-te-ondertekenen*

Vanaf 2 augustus 2026 zijn aanbieders en gebruikers van AI-systemen verplicht duidelijk te maken wanneer mensen met artificiële intelligentie (AI) te maken hebben. De Europese Commissie heeft op 10 juni een praktijkcode gepubliceerd waarin een deel van deze transparantieverplichtingen verder is uitgewerkt. De Autoriteit Persoonsgegevens (AP) adviseert organisaties die onder deze verplichtingen vallen zich te verdiepen in de praktijkcode en (onderdelen ervan) te ondertekenen. Organisaties die voo

## Related topics

- **Provider Obligations for AI Systems** — https://overview.legal/topics/provider-obligations-ai
  The content specifically addresses obligations imposed on providers of high-risk AI systems, which is a distinct and important category of requirements that des
- **Conformity Assessment for AI Systems** — https://overview.legal/topics/conformity-assessment-ai
  Provider obligations typically include conformity assessment procedures and documentation requirements, which is a specific compliance mechanism under the AI Ac
- **Technical Documentation for AI Systems** — https://overview.legal/topics/technical-documentation-ai
  The AI Act imposes specific technical documentation requirements for AI systems, particularly high-risk AI systems. This dedicated topic would cover the mandato
- **Documentation Keeping for AI Systems** — https://overview.legal/topics/documentation-keeping-ai
  While 'record-keeping-ai' exists, a more specific topic focused on documentation keeping as a distinct concept would better capture the AI Act's specific requir
- **AI Record-Keeping** — https://overview.legal/topics/record-keeping-ai
  The AI Act imposes specific record-keeping obligations for AI systems that are distinct from general GDPR record-keeping. A dedicated topic would capture AI-spe
- **AI Value Chain Actors and Roles** — https://overview.legal/topics/ai-value-chain-actors
  The content focuses on responsibilities distributed across different actors in the AI value chain. A dedicated topic for understanding the various actors, their

---
Generated by overview.legal · https://overview.legal/topics/ai-act-requirements · 2026-08-22
