Browse all tools and resources →

Read me Page help ↗
Observatory

SR 26-2 vs EU AI Act

The same obligation themes, side by side, from the catalogue that powers the rest of this site — 17 catalogued requirements across 15 themes. Expand any requirement to read it. Free, no login.

Comparing 2 of 38 regulations we track. This URL is the comparison — send it to anyone.

Guidance

SR 26-2 — Interagency Model Risk Management Guidance (successor to SR 11-7)

Authority
US Fed / OCC / FDIC · USA (banking)
Catalogued requirements
2, none mandatory
Themes it legislates on
2 of the 15 below
Maximum exposure
Supervisory findings (MRAs) for regulated banks
Next dated obligation
Nothing dated ahead in our calendar
Official source last read
2026-10-07 — unchanged since our last read
In force

EU Artificial Intelligence Act (Reg. 2024/1689)

Authority
European Union · EU / EEA
Catalogued requirements
15, all mandatory
Themes it legislates on
15 of the 15 below
Maximum exposure
Up to €35M or 7% of global annual turnover (GPAI-specific: up to €15M or 3%)
Next dated obligation
2026-12-02 — EU AI Act — NCII/CSAM ban + end of marking grace period (in 55 days)
Official source last read
2026-10-07 — unchanged since our last read

Where they overlap

Every theme below appears in exactly one group, so these account for all 15 of them. Sharing a theme means both regimes legislate in that area — it does not mean complying with one discharges the other.

Both legislate here · 2 themes

SR 26-2 · EU AI Act

Risk management systemAccuracy, robustness & security

1 of the 2 legislates here · 13 themes

EU AI Actnot: SR 26-2

Outright bansRights impact assessmentData & training dataTechnical documentationConformity assessmentRegistration & public listingTransparency & explanationTelling people AI was usedLabelling AI-generated contentHuman oversight & overrideLogging & recordsMonitoring after deploymentIncident reporting

Requirement by requirement

A dash means we have not catalogued a requirement for that regulation under that theme — a summary of our catalogue, not a finding that the law is silent. Always check the official text, linked from each regulation's page.

ThemeSR 26-2EU AI Act
What is forbidden outright
Outright bans Are some uses forbidden regardless of safeguards? —
Art. 5 Prohibited AI practices must

Practices such as social scoring, manipulative/subliminal techniques, exploitation of vulnerabilities, untargeted facial scraping, and (most) real-time remote biometric identification are banned and cannot be placed on the EU market.

Read it in context →
What you must assess first
Risk management system Must you run a documented, continuous risk process?
Inventory Model inventory & tiering should

Maintain a complete model inventory tiered by materiality, with documented development evidence for each model.

Read it in context →
Art. 9 Risk-management system must

Establish, document and maintain a continuous risk-management system across the AI lifecycle.

Read it in context →
Rights impact assessment Must you assess the impact on people before deploying? —
Art. 27 Fundamental Rights Impact Assessment must

Certain deployers must perform a Fundamental Rights Impact Assessment before putting the system into use.

Read it in context →
What you owe the data
Data & training data Are there duties on the data the system learns from? —
Art. 10 Data & data governance must

Training, validation and testing data must meet quality criteria and be examined for bias; document provenance and representativeness.

Read it in context →
What you must build and prove
Accuracy, robustness & security Must you hit and evidence performance targets?
Validation Independent validation & monitoring should

Independent validation covering conceptual soundness, ongoing monitoring (incl. benchmarking) and outcomes analysis/backtesting; change management triggers revalidation; vendor models validated too.

Read it in context →
Art. 15 Accuracy, robustness & cybersecurity must

Achieve appropriate accuracy, robustness and cybersecurity, and declare metrics.

Read it in context →
Technical documentation Must a technical file exist before deployment? —
Art. 11 / Annex IV Technical documentation must

Draw up and keep up-to-date technical documentation demonstrating conformity (the Annex IV technical file).

Read it in context →
Conformity assessment Must someone certify it before it goes to market? —
Art. 43 Conformity assessment must

Undergo the relevant conformity-assessment procedure and draw up an EU declaration of conformity before market entry.

Read it in context →
Registration & public listing Must the system be registered or published somewhere? —
Art. 49 EU database registration must

Register the high-risk system in the EU database before placing it on the market.

Read it in context →
What you must tell people
Transparency & explanation Must you explain how it works, and to whom? —
Art. 13 Transparency & instructions for use must

Provide deployers with clear instructions: capabilities, limitations, and required human oversight.

Read it in context →
Telling people AI was used Must people be told an AI was involved? —
Art. 50 Transparency for certain systems must

Inform people they are interacting with an AI system (chatbots) and label AI-generated/manipulated content.

Read it in context →
Labelling AI-generated content Must generated output be marked or watermarked? —
Art. 50(2) Marking of synthetic content must

Mark AI-generated audio, image, video or text in a machine-readable, detectable way.

Read it in context →
What you must do while it runs
Human oversight & override Must a person be able to intervene, review or stop it? —
Art. 14 Human oversight must

Design the system so humans can effectively oversee it, intervene, and stop it.

Read it in context →
Logging & records Must the system keep records of what it did? —
Art. 12 Record-keeping (logging) must

Automatically record events (logs) over the system lifetime to ensure traceability.

Read it in context →
Monitoring after deployment Must you keep watching it once it is live? —
Art. 72 Post-market monitoring must

Operate a post-market monitoring system to collect and review performance data after deployment.

Read it in context →
Incident reporting Must failures be reported, and to whom? —
Art. 73 Serious-incident reporting must

Report serious incidents and malfunctioning to the competent market-surveillance authority.

Read it in context →

Which one bites first

Every dated obligation attached to these regulations, merged into one timeline.

EU AI Act 2025-07-10 · in force

EU AI Act — GPAI Code of Practice published

The final GPAI Code of Practice (Transparency, Copyright, Safety & Security chapters) gives providers a voluntary route to demonstrate compliance ahead of harmonised standards.

EU AI Act 2026-08-02 · in force

EU AI Act — Art. 50 transparency obligations in force

Now live. Chatbots must disclose they are AI; deepfakes and emotion-recognition/biometric-categorisation uses must be disclosed. The Commission adopted final Art. 50 guidelines on 20 July 2026, and the AI Office's enforcement powers over GPAI providers (fines up to €15M or 3% of turnover) became applicable the same day. Providers' machine-readable marking of synthetic content under Art. 50(2) has a grace period to 2 Dec 2026.

EU AI Act 2027-12-02 · in 420 days

EU AI Act — serious-incident reporting (Art. 73)

Providers of high-risk systems must report serious incidents to authorities within 15 days (10 days on a death; 2 days for widespread infringement or critical-infrastructure disruption).

EU AI Act 2027-12-02 · in 420 days

EU AI Act — Annex III high-risk obligations apply

Full high-risk regime (risk management, data governance, logging, human oversight, accuracy, conformity assessment, registration). Moved from Aug 2026 to 2 Dec 2027 by the Digital Omnibus — Regulation (EU) 2026/1744, published in the Official Journal 24 July 2026 and in force since 27 July 2026, so this date is settled law.

EU AI Act 2028-08-02 · in 664 days

EU AI Act — Annex I embedded high-risk obligations apply

High-risk AI embedded in regulated products (machinery, medical devices, vehicles) must comply. Moved from Aug 2027 to 2 Aug 2028 by the Digital Omnibus — Regulation (EU) 2026/1744, in force since 27 July 2026.