EU AI Act
The first fully populated catalog, and the one with an obligation already in force that the gateway can evidence directly: Art 50(1), the AI-interaction notice, applies from 2 August 2026. Dates follow the Digital Omnibus on AI (Regulation (EU) 2026/1744), which moved Annex III standalone high-risk duties to 2 December 2027 and Annex I embedded systems to 2 August 2028, added prohibitions from 2 December 2026, and extended Art 50(2) marking to legacy systems from the same day.
| Registry id | eu-ai-act |
| Kind | regulation |
| Jurisdiction | EU |
| Instrument | Regulation (EU) 2024/1689, as amended by Regulation (EU) 2026/1744 |
| Catalog versions | 2024-08 from 2024-08-01 until 2026-07-27 — Regulation (EU) 2024/1689 as published; 2026-09 from 2026-07-27 (current) — As amended by the Digital Omnibus on AI, Regulation (EU) 2026/1744 |
| Verified against instrument | yes |
| Tagging key (compliance tags) | eu_ai_act |
Roles (frameworks.eu-ai-act.role) |
authorised_representative, deployer, distributor, importer, product_manufacturer, provider, provider_and_deployer |
Classifications (frameworks.eu-ai-act.risk_tier) |
high, limited, minimal, unacceptable |
| Incident deadline rules | standard: 15 days, death: 10 days, widespread: 2 days |
| Retention floors | high: 183 days |
| Obligations | 30 |
The catalog has two versions. 2024-08 (in force until 27 July 2026) carries the dates as originally published; 2026-09 carries the Omnibus dates. A statement is evaluated against the version in force on the action’s date, so a report over an older window keeps the older dates.
Deadline rules
Section titled “Deadline rules”Alternative rules: the incident’s classification picks the rule when it names one, else standard applies.
| Rule | Deadline from became_aware_at |
|---|---|
standard |
15 days |
death |
10 days |
widespread |
2 days |
Deadlines are computed and shown, never enforced — see incidents.
How applicability is computed
Section titled “How applicability is computed”Each obligation is evaluated per AI System from the facts declared on its compliance profile — the eu-ai-act block’s role and risk_tier (written through to the resource group’s eu_ai_act_role / eu_ai_act_risk_tier columns, so nothing that existed before breaks), the neutral-core flags such as interacts_with_natural_persons, and the GPAI classification of the models the system binds (flag models gpai / gpai_systemic_risk in the Asset Register; Art 53–55 attach to the model).
Composite systems. The catalog sets composite classification: a system is evaluated at
its effective tier — the highest of its declared risk_tier and the tier of every AI
System that declares a contributing dependency on it (composite systems).
A fraud screener declared minimal under the Art 6(3) carve-out that feeds a high-risk
credit decision is evaluated at high; its declared tier stays visible as a claim. A
dependency declared non-contributing (with a sealed separability rationale) keeps its own tier.
The board models “obligation X applies to system Y from date Z”, never “system Y is compliant: true” — a boolean dies at the next omnibus, a dated applicability survives it. Three statuses per (obligation, system):
| Status | Meaning |
|---|---|
| applies | The system’s declared facts put it in scope. |
| not applicable | A declared fact rules it out (e.g. minimal risk → no high-risk duties). |
| undetermined | The system has not declared the fact the rule needs. An undeclared role cannot rule an obligation out — the honest answer is “declare it”, shown as a to-do, never a pass. |
Obligations the platform cannot evaluate alone (whether a system is embedded in an Annex I product, a legacy placement date, whether a deployer is in Art 27 scope) carry a review note naming the determination you need to record. Art 25 can turn a deployer into a provider on rebranding or substantial modification; a contract drift on the system’s closure is exactly that signal — review the role when one fires.
Old obligation keys (annex3-provider-duties, annex3-deployer-duties, art50-transparency, art72-post-market) still resolve: GET /v1/admin/compliance/obligations/{key} maps them to their successors.
Obligations and their evidence
Section titled “Obligations and their evidence”Each obligation lists the statements it is shown against. The basis is one of recomputed, judged, indicator or declared (what the bases mean); the resolver is from the shared library.
AI literacy
Section titled “AI literacy”art4-ai-literacy · Art 4 · applies from 2025-02-02
Staff dealing with the operation and use of AI systems must have a sufficient level of AI literacy. Applies to providers and deployers of any AI system. Applies to every system for which the framework is active.
What the gateway cannot show: Organisational duty, evidenced by declaration only.
| Statement | Basis | Resolver | Does not show |
|---|---|---|---|
| An AI literacy programme is declared. | declared | profile.field_declared {"path": "frameworks.eu-ai-act.ai_literacy_reference"} |
Training is organisational; the gateway cannot observe it. |
Prohibited practices
Section titled “Prohibited practices”art5-prohibitions · Art 5 · applies from 2025-02-02
Practices classified as unacceptable risk are banned outright. Every system is subject to the prohibitions; a system classified unacceptable may not be operated. Applies to every system for which the framework is active.
| Statement | Basis | Resolver | Does not show |
|---|---|---|---|
| Sampled runs show no manipulative or deceptive technique. | judged | judge.no_manipulation |
Judged by a model over a disclosed sample; stated with human agreement, never merged with recomputed rows. |
Additional prohibited practices (Omnibus)
Section titled “Additional prohibited practices (Omnibus)”art5-prohibitions-2026 · Art 5 as amended by Reg. 2026/1744 · applies from 2026-12-02 · introduced in catalog 2026-09
The prohibitions added by the Digital Omnibus on AI apply from 2 December 2026. Applies to every system for which the framework is active.
| Statement | Basis | Resolver | Does not show |
|---|---|---|---|
| Sampled runs show no manipulative or deceptive technique. | judged | judge.no_manipulation |
Judged by a model over a disclosed sample; stated with human agreement, never merged with recomputed rows. |
Risk management system
Section titled “Risk management system”art9-risk-management · Art 9 · applies from 2027-12-02 · earlier catalog: 2024-08 → 2026-08-02
A continuous, iterative risk-management process across the system’s lifecycle. Applies to: classification high; roles authorised_representative, distributor, importer, product_manufacturer, provider, provider_and_deployer.
What the gateway cannot show: Organisational duty, evidenced by pointer only.
| Statement | Basis | Resolver | Does not show |
|---|---|---|---|
| A current risk assessment is on file. | recomputed | evidence.pointer_on_file {"kind": "risk_assessment"} |
A pointer to a document produced outside the platform; its content is not evaluated. |
Data and data governance
Section titled “Data and data governance”art10-data-governance · Art 10 · applies from 2027-12-02 · earlier catalog: 2024-08 → 2026-08-02
Training, validation and testing data meet the quality criteria of Art 10. Applies to: classification high; roles authorised_representative, distributor, importer, product_manufacturer, provider, provider_and_deployer.
What the gateway cannot show: Training data is outside the gateway; evidenced by pointer only.
| Statement | Basis | Resolver | Does not show |
|---|---|---|---|
| A data-governance record is on file. | recomputed | evidence.pointer_on_file {"kind": "data_governance"} |
A pointer to a document produced outside the platform; its content is not evaluated. |
Technical documentation
Section titled “Technical documentation”art11-technical-documentation · Art 11, Annex IV · applies from 2027-12-02 · earlier catalog: 2024-08 → 2026-08-02
Technical documentation drawn up before placing on the market and kept current. Applies to: classification high; roles authorised_representative, distributor, importer, product_manufacturer, provider, provider_and_deployer.
| Statement | Basis | Resolver | Does not show |
|---|---|---|---|
| A documentation export exists for the active contract version, with its digest sealed. | recomputed | docs.technical_documentation {"framework": "eu-ai-act"} |
A skeleton generated from the register and contract; its adequacy is not evaluated. |
Record-keeping (automatic logging)
Section titled “Record-keeping (automatic logging)”art12-record-keeping · Art 12 · applies from 2027-12-02 · earlier catalog: 2024-08 → 2026-08-02
Automatic recording of events over the system’s lifetime, enabling traceability and post-market monitoring. Applies to: classification high; roles authorised_representative, distributor, importer, product_manufacturer, provider, provider_and_deployer.
| Statement | Basis | Resolver | Does not show |
|---|---|---|---|
| Every governed action produced a sealed record, including refusals. | recomputed | records.every_verdict_sealed |
Integrity is not completeness: covers actions routed through the gateway only; records sealed late by backfill are reported separately. |
| The tenant log’s tree heads covering the window were witnessed by an independent service. | recomputed | records.witnessed |
A receipt shows inclusion at a tree size, not a witness-observed time; a same-operator witness is self-attested. |
| Approval chains are closed and epoch boundaries match the contract history. | recomputed | records.chain_complete |
Checks the chains the gateway opened; actions that never reached the gateway cannot be counted. |
Transparency and information to deployers
Section titled “Transparency and information to deployers”art13-transparency-to-deployers · Art 13 · applies from 2027-12-02 · earlier catalog: 2024-08 → 2026-08-02
Instructions for use enabling deployers to interpret output and use the system appropriately. Applies to: classification high; roles authorised_representative, distributor, importer, product_manufacturer, provider, provider_and_deployer.
| Statement | Basis | Resolver | Does not show |
|---|---|---|---|
| A documentation export exists for the active contract version, with its digest sealed. | recomputed | docs.technical_documentation {"framework": "eu-ai-act"} |
A skeleton generated from the register and contract; its adequacy is not evaluated. |
| Instructions for use are declared. | declared | profile.field_declared {"path": "frameworks.eu-ai-act.instructions_for_use_reference"} |
The instructions’ content is not evaluated. |
Human oversight
Section titled “Human oversight”art14-human-oversight · Art 14 · applies from 2027-12-02 · earlier catalog: 2024-08 → 2026-08-02
Designed so natural persons can oversee, interpret, override and stop the system. Applies to: classification high; roles authorised_representative, distributor, importer, product_manufacturer, provider, provider_and_deployer.
| Statement | Basis | Resolver | Does not show |
|---|---|---|---|
| A human can override or stop the system. | recomputed | oversight.override_available |
Shows the controls exist and are assigned, not that the assigned people are competent. |
| Human approval requests were decided by humans (requested, decided, lapsed). | recomputed | oversight.exercised |
Records the fact of human disposition, not its quality. |
| Approval latency and denial rate are tracked for movement. | indicator | oversight.not_rubber_stamp |
An indicator of movement, never a threshold; it cannot show a decision was considered. |
| Sampled approval decisions carry a rationale consistent with the request. | judged | judge.approval_rationale |
Judged by a model over a disclosed sample; stated with human agreement, never merged with recomputed rows. |
Accuracy, robustness and cybersecurity
Section titled “Accuracy, robustness and cybersecurity”art15-accuracy-robustness · Art 15 · applies from 2027-12-02 · earlier catalog: 2024-08 → 2026-08-02
Appropriate accuracy, robustness and cybersecurity, declared in the instructions for use. Applies to: classification high; roles authorised_representative, distributor, importer, product_manufacturer, provider, provider_and_deployer.
| Statement | Basis | Resolver | Does not show |
|---|---|---|---|
| A current evaluation report is on file. | recomputed | evidence.pointer_on_file {"kind": "eval_report"} |
A pointer to a document produced outside the platform; its content is not evaluated. |
| A current red-team report is on file. | recomputed | evidence.pointer_on_file {"kind": "red_team_report"} |
A pointer to a document produced outside the platform; its content is not evaluated. |
Quality management system
Section titled “Quality management system”art17-quality-management · Art 17 · applies from 2027-12-02 · earlier catalog: 2024-08 → 2026-08-02
A documented quality management system. Applies to: classification high; roles authorised_representative, distributor, importer, product_manufacturer, provider, provider_and_deployer.
What the gateway cannot show: Organisational duty, evidenced by declaration only.
| Statement | Basis | Resolver | Does not show |
|---|---|---|---|
| A quality management system is declared. | declared | profile.field_declared {"path": "frameworks.eu-ai-act.qms_reference"} |
Organisational duty; the QMS itself is not evaluated. |
Automatically generated logs (provider)
Section titled “Automatically generated logs (provider)”art19-log-retention-provider · Art 19 · applies from 2027-12-02 · earlier catalog: 2024-08 → 2026-08-02
Providers keep the automatically generated logs under their control for at least six months. Applies to: classification high; roles authorised_representative, distributor, importer, product_manufacturer, provider, provider_and_deployer.
| Statement | Basis | Resolver | Does not show |
|---|---|---|---|
| Logs are kept for at least six months (183 days). | recomputed | retention.floor {"floor_days": 183} |
Record identifiers, statements and tree heads are permanent; bodies follow retention. |
| Every gap in the retained logs is a declared prune. | recomputed | retention.declared_prunes |
— |
Classification of a composite system
Section titled “Classification of a composite system”art6-composite-classification · Art 6; Recital 12; draft Commission high-risk classification guidelines (May 2026) · applies from 2027-12-02 · earlier catalog: 2024-08 → 2026-08-02
Where components’ combined outputs materially influence a high-risk decision they are treated as one system: a contributing component is assessed with it, unless it is genuinely separable and does not contribute to the high-risk purpose. Applies to: classification high.
Review: Rests on the Commission’s DRAFT classification guidelines (consultation closed 23 June 2026); re-check against the final text.
What the gateway cannot show: Covers declared dependency edges; the composition checks report undeclared delegation.
| Statement | Basis | Resolver | Does not show |
|---|---|---|---|
| Every dependency that contributes to this system’s decisions is assessed at its tier, or carries a sealed separability rationale. | recomputed | dependencies.contributing_assessed |
Counts declared dependency edges only; an undeclared delegation is a composition finding, not a statement input. An external agent’s assessment is evidenced by supplier information, not examined. |
Written agreements with suppliers
Section titled “Written agreements with suppliers”art25-4-supplier-agreements · Art 25(4) · applies from 2027-12-02 · earlier catalog: 2024-08 → 2026-08-02
Third parties supplying AI systems, tools, services or components used in a high-risk system give the provider, by written agreement, the information, capabilities and technical access it needs to comply. Applies to: classification high; roles authorised_representative, distributor, importer, product_manufacturer, provider, provider_and_deployer.
What the gateway cannot show: Evidenced by pointer to the agreement; its terms are not evaluated.
| Statement | Basis | Resolver | Does not show |
|---|---|---|---|
| Every dependency supplied by another legal entity has the supplier’s written information on file. | recomputed | dependencies.supplier_information_on_file |
A pointer to the agreement, pinned by hash; its content is not evaluated. |
Use in accordance with instructions
Section titled “Use in accordance with instructions”art26-1-use-per-instructions · Art 26(1) · applies from 2027-12-02 · earlier catalog: 2024-08 → 2026-08-02
Deployers use the system in accordance with the instructions for use. Applies to: classification high; roles deployer, provider_and_deployer.
| Statement | Basis | Resolver | Does not show |
|---|---|---|---|
| Every action outside the contract or grant was refused. | recomputed | authz.out_of_grant_refused |
Covers actions the gateway observed; the grant itself is a declaration. |
| Sampled runs stay within the declared intended use. | judged | judge.per_instructions |
Judged by a model over a disclosed sample; stated with human agreement, never merged with recomputed rows. |
Human oversight assignment
Section titled “Human oversight assignment”art26-2-oversight-assignment · Art 26(2) · applies from 2027-12-02 · earlier catalog: 2024-08 → 2026-08-02
Human oversight is assigned to natural persons with the necessary competence and authority. Applies to: classification high; roles deployer, provider_and_deployer.
| Statement | Basis | Resolver | Does not show |
|---|---|---|---|
| A human can override or stop the system. | recomputed | oversight.override_available |
Shows the controls exist and are assigned, not that the assigned people are competent. |
Monitoring and suspension
Section titled “Monitoring and suspension”art26-5-monitoring-and-suspend · Art 26(5) · applies from 2027-12-02 · earlier catalog: 2024-08 → 2026-08-02
Deployers monitor operation and suspend use where the system presents a risk. Applies to: classification high; roles deployer, provider_and_deployer.
| Statement | Basis | Resolver | Does not show |
|---|---|---|---|
| Liveness, drift and health were evaluated every day. | recomputed | monitoring.daily_health |
— |
| Suspension and run-abort controls are available and every use of them was sealed. | recomputed | monitoring.suspend_available |
— |
Log retention (deployer)
Section titled “Log retention (deployer)”art26-6-log-retention-deployer · Art 26(6) · applies from 2027-12-02 · earlier catalog: 2024-08 → 2026-08-02
Deployers keep the automatically generated logs under their control for at least six months. Applies to: classification high; roles deployer, provider_and_deployer.
| Statement | Basis | Resolver | Does not show |
|---|---|---|---|
| Logs are kept for at least six months (183 days). | recomputed | retention.floor {"floor_days": 183} |
Record identifiers, statements and tree heads are permanent; bodies follow retention. |
Information to workers
Section titled “Information to workers”art26-7-worker-information · Art 26(7) · applies from 2027-12-02 · earlier catalog: 2024-08 → 2026-08-02
Workers’ representatives and affected workers are informed before workplace use. Applies to: classification high; roles deployer, provider_and_deployer.
What the gateway cannot show: Organisational duty, evidenced by declaration only.
| Statement | Basis | Resolver | Does not show |
|---|---|---|---|
| Worker information is declared. | declared | profile.field_declared {"path": "frameworks.eu-ai-act.worker_information_reference"} |
Organisational duty; the information given is not evaluated. |
Fundamental rights impact assessment
Section titled “Fundamental rights impact assessment”art27-fria · Art 27 · applies from 2027-12-02 · earlier catalog: 2024-08 → 2026-08-02
Bodies governed by public law, private entities providing public services, and deployers of Annex III 5(b)/(c) systems assess the impact on fundamental rights. Applies to: classification high; roles deployer, provider_and_deployer.
Review: Applies to public bodies, public-service providers and Annex III 5(b)/(c) deployers — confirm whether the deployer is in scope.
| Statement | Basis | Resolver | Does not show |
|---|---|---|---|
| A fundamental rights impact assessment is on file. | recomputed | evidence.pointer_on_file {"kind": "impact_assessment"} |
A pointer to a document produced outside the platform; its content is not evaluated. |
Registration in the EU database
Section titled “Registration in the EU database”art49-registration · Art 49, Art 71 · applies from 2027-12-02 · earlier catalog: 2024-08 → 2026-08-02
High-risk systems (and, for public bodies, their use) are registered in the EU database. Applies to: classification high.
| Statement | Basis | Resolver | Does not show |
|---|---|---|---|
| The EU database registration identifier is recorded. | declared | docs.registration_recorded {"framework": "eu-ai-act"} |
The identifier is declared; the registry entry itself is not queried. |
AI-interaction notice
Section titled “AI-interaction notice”art50-1-ai-interaction-notice · Art 50(1) · applies from 2026-08-02
People interacting with an AI system are informed they are interacting with an AI, unless obvious from the circumstances. Applies to: profile flag core.interacts_with_natural_persons.
| Statement | Basis | Resolver | Does not show |
|---|---|---|---|
| People were told they were dealing with an AI before the first substantive turn. | recomputed | notice.before_first_turn |
Counts conversations through the Brutor portal (notice records); other clients must render their own notice. |
| The notice text and the surface it is shown on are declared and sealed. | declared | notice.text_declared |
— |
| Sampled notices are clear and distinguishable. | judged | judge.notice_clear |
Judged by a model over a disclosed sample; stated with human agreement, never merged with recomputed rows. |
Marking of synthetic content
Section titled “Marking of synthetic content”art50-2-synthetic-marking · Art 50(2) · applies from 2026-08-02
Synthetic audio, image, video or text outputs are marked in a machine-readable format. Applies to: profile flag core.generates_synthetic_content.
What the gateway cannot show: Content-level marking is not provided by the gateway.
| Statement | Basis | Resolver | Does not show |
|---|---|---|---|
| The approach to marking synthetic content is declared. | declared | synthetic.marking_declared |
Content-level marking (watermarking, C2PA) is not provided; outputs carry an X-Brutor-AI-Generated header only. |
Synthetic-content marking for legacy systems
Section titled “Synthetic-content marking for legacy systems”art50-legacy · Art 50(2) as amended by Reg. 2026/1744 · applies from 2026-12-02 · introduced in catalog 2026-09
Art 50(2) marking duties extend to systems placed on the market before 2 August 2026. Applies to: profile flag core.generates_synthetic_content.
Review: Applies to systems placed on the market before 2 August 2026 — confirm the placement date.
| Statement | Basis | Resolver | Does not show |
|---|---|---|---|
| The approach to marking synthetic content is declared. | declared | synthetic.marking_declared |
Content-level marking (watermarking, C2PA) is not provided; outputs carry an X-Brutor-AI-Generated header only. |
Deep fake and public-interest text disclosure
Section titled “Deep fake and public-interest text disclosure”art50-4-deepfake-text-disclosure · Art 50(4) · applies from 2026-08-02
Deployers disclose deep fakes, and AI-generated text published to inform the public on matters of public interest. Applies to: roles deployer, provider_and_deployer; profile flag core.generates_synthetic_content.
| Statement | Basis | Resolver | Does not show |
|---|---|---|---|
| The disclosure approach for deep fakes and public-interest text is declared. | declared | profile.field_declared {"path": "frameworks.eu-ai-act.deepfake_disclosure_approach"} |
Publication happens outside the gateway; the disclosure is not observed. |
Post-market monitoring
Section titled “Post-market monitoring”art72-post-market-monitoring · Art 72 · applies from 2027-12-02 · earlier catalog: 2024-08 → 2026-08-02
A post-market monitoring system proportionate to the risks, fed by production evidence — the run ledger and drift findings are the raw material. Applies to: classification high; roles authorised_representative, distributor, importer, product_manufacturer, provider, provider_and_deployer.
| Statement | Basis | Resolver | Does not show |
|---|---|---|---|
| Liveness, drift and health were evaluated every day. | recomputed | monitoring.daily_health |
— |
Reporting of serious incidents
Section titled “Reporting of serious incidents”art73-serious-incidents · Art 73 · applies from 2027-12-02 · earlier catalog: 2024-08 → 2026-08-02
Serious incidents are reported to the market surveillance authority: within 15 days of awareness; 10 days on a death; 2 days when widespread or critical infrastructure is affected. Applies to: classification high.
| Statement | Basis | Resolver | Does not show |
|---|---|---|---|
| An incident register is kept and no open incident is past its deadline. | recomputed | incidents.register_exists |
— |
| Serious incidents were reported within the Art 73 deadline (15 days; death 10; widespread 2). | recomputed | incidents.reported_within_deadline {"framework": "eu-ai-act"} |
Deadlines are computed and shown, not enforced; awareness time is operator-entered. |
High-risk duties for Annex I embedded systems
Section titled “High-risk duties for Annex I embedded systems”annex1-embedded · Annex I, Art 6(1) · applies from 2028-08-02 · earlier catalog: 2024-08 → 2027-08-02
High-risk duties where the AI system is a safety component of (or is itself) an Annex I regulated product — machinery, medical devices, vehicles… Applies to: classification high.
Review: Brutor cannot infer whether the system is embedded in an Annex I product — review and record the determination.
| Statement | Basis | Resolver | Does not show |
|---|---|---|---|
| The Annex I / Annex III determination is declared. | declared | profile.field_declared {"path": "frameworks.eu-ai-act.annex"} |
The determination is the operator’s; it is not evaluated. |
GPAI model provider duties
Section titled “GPAI model provider duties”art53-gpai · Art 53, Annex XI/XII · applies from 2025-08-02
Technical documentation, downstream information, copyright policy and training-content summary for general-purpose AI models. Attaches to the MODEL provider — this system is exposed through the GPAI models it binds. Applies to: systems binding a gpai model.
| Statement | Basis | Resolver | Does not show |
|---|---|---|---|
| The GPAI provider’s downstream documentation is referenced. | declared | profile.field_declared {"path": "frameworks.eu-ai-act.gpai_documentation_reference"} |
Model-provider duty; the documentation is not evaluated. |
Systemic-risk GPAI duties
Section titled “Systemic-risk GPAI duties”art55-gpai-systemic · Art 55 · applies from 2025-08-02
Model evaluation, adversarial testing, incident reporting and cybersecurity for GPAI models designated as systemic-risk. Attaches to the MODEL provider. Applies to: systems binding a gpai_systemic_risk model.
| Statement | Basis | Resolver | Does not show |
|---|---|---|---|
| The GPAI provider’s downstream documentation is referenced. | declared | profile.field_declared {"path": "frameworks.eu-ai-act.gpai_documentation_reference"} |
Model-provider duty; the documentation is not evaluated. |
Related
Section titled “Related”- Framework registry & evidence bases — how catalogs, resolvers and the version in force work
- The Compliance console — the Obligations matrix for this framework
- Incidents, reports & documentation

