This page is a plain-English summary written by us, not legal advice — the official text is linked above. Our catalogue was last reviewed 2026-08-15; that is a review of the whole catalogue, not an independent legal verification of this entry.
Requirements (15)
Art. 5
mandatory
Practices such as social scoring, manipulative/subliminal techniques, exploitation of vulnerabilities, untargeted facial scraping, and (most) real-time remote biometric identification are banned and cannot be placed on the EU market.
Satisfied by: Prohibited practices screen
Art. 9
mandatory
Establish, document and maintain a continuous risk-management system across the AI lifecycle.
Satisfied by: Risk management system · Equivalent: NIST AI RMF 1.0 MANAGE 1.2, NIST AI RMF 1.0 MANAGE 1.3, NIST AI RMF 1.0 MAP 5.1, ISO/IEC 42001:2023 Annex A A.5.2, NIST AI RMF 1.0 GOVERN 1.3, NIST AI RMF 1.0 GOVERN 1.4, NIST AI RMF 1.0 MAP 1.5, NIST AI RMF 1.0 MANAGE 1.4
Art. 10
mandatory
Training, validation and testing data must meet quality criteria and be examined for bias; document provenance and representativeness.
Satisfied by: Data & data governance · Equivalent: NIST AI RMF 1.0 MEASURE 2.11, NIST AI RMF 1.0 MAP 2.3, ISO/IEC 42001:2023 Annex A A.7.2, ISO/IEC 42001:2023 Annex A A.7.4, ISO/IEC 42001:2023 Annex A A.7.5, NIST AI RMF 1.0 MEASURE 2.10, ISO/IEC 42001:2023 Annex A A.4.3, ISO/IEC 42001:2023 Annex A A.7.3, ISO/IEC 42001:2023 Annex A A.7.6
When this failed: Amazon recruiting tool biased against women · Apple Card credit-limit gender-bias claims · Ad-delivery algorithm enabled housing discrimination · Model data poisoning (PoisonGPT)
Art. 11 / Annex IV
mandatory
Draw up and keep up-to-date technical documentation demonstrating conformity (the Annex IV technical file).
Art. 12
mandatory
Automatically record events (logs) over the system lifetime to ensure traceability.
Satisfied by: Record-keeping (logging) · Equivalent: ISO/IEC 42001:2023 Annex A A.6.2.8
Art. 13
mandatory
Provide deployers with clear instructions: capabilities, limitations, and required human oversight.
Satisfied by: Instructions for use · Equivalent: NIST AI RMF 1.0 MAP 2.2, NIST AI RMF 1.0 MEASURE 2.8, ISO/IEC 42001:2023 Annex A A.8.2, NIST AI RMF 1.0 MAP 1.1, NIST AI RMF 1.0 MAP 3.3, NIST AI RMF 1.0 MEASURE 2.9, NIST AI RMF 1.0 MANAGE 1.4
Art. 14
mandatory
Design the system so humans can effectively oversee it, intervene, and stop it.
Satisfied by: Human oversight · Equivalent: NIST AI RMF 1.0 GOVERN 3.2, NIST AI RMF 1.0 MAP 3.5, NIST AI RMF 1.0 MANAGE 2.4, ISO/IEC 42001:2023 Annex A A.9.2, NIST AI RMF 1.0 MAP 2.2, NIST AI RMF 1.0 MAP 3.4, NIST AI RMF 1.0 MEASURE 2.6
When this failed: COMPAS recidivism scores racially biased · Dutch benefits-fraud algorithm discriminated · Over-reliance on driver-assist automation · Coding agent deleted a production database · AI hiring tool auto-rejected older applicants · UK A-level grading algorithm downgraded students · Algorithm auto-denied insurance claims at scale · Air Canada chatbot gave a false refund policy · Lawyer filed AI-hallucinated case citations · Solely-automated decision without safeguards
Art. 15
mandatory
Achieve appropriate accuracy, robustness and cybersecurity, and declare metrics.
Satisfied by: Accuracy, robustness & cybersecurity · Equivalent: NIST AI RMF 1.0 MEASURE 2.5, NIST AI RMF 1.0 MEASURE 2.7, ISO/IEC 42001:2023 Annex A A.6.2.4, NIST AI RMF 1.0 MEASURE 1.1, NIST AI RMF 1.0 MEASURE 2.3, NIST AI RMF 1.0 MEASURE 2.6
When this failed: Knight Capital runaway trading algorithm · Over-reliance on driver-assist automation · Indirect prompt-injection data exfiltration · $25M lost to a deepfake video-call CEO · Model data poisoning (PoisonGPT) · Microsoft Tay turned toxic within hours · Hallucinated package names enable supply-chain attacks
Art. 27
mandatory
Certain deployers must perform a Fundamental Rights Impact Assessment before putting the system into use.
Satisfied by: Fundamental rights impact assessment · Equivalent: NIST AI RMF 1.0 MAP 5.1, ISO/IEC 42001:2023 Annex A A.5.2, ISO/IEC 42001:2023 Annex A A.5.4
When this failed: Dutch benefits-fraud algorithm discriminated · UK A-level grading algorithm downgraded students
Art. 43
mandatory
Undergo the relevant conformity-assessment procedure and draw up an EU declaration of conformity before market entry.
Satisfied by: Conformity assessment · Equivalent: NIST AI RMF 1.0 MEASURE 1.3, ISO/IEC 42001:2023 Annex A A.6.2.5
Art. 49
mandatory
Register the high-risk system in the EU database before placing it on the market.
Satisfied by: EU database registration · Equivalent: NIST AI RMF 1.0 GOVERN 1.6
Art. 50
mandatory
Inform people they are interacting with an AI system (chatbots) and label AI-generated/manipulated content.
Satisfied by: Transparency obligations · Equivalent: NIST AI RMF 1.0 MEASURE 2.8
When this failed: Dealer chatbot jailbroken into a $1 car offer
Art. 50(2)
mandatory
Mark AI-generated audio, image, video or text in a machine-readable, detectable way.
Art. 72
mandatory
Operate a post-market monitoring system to collect and review performance data after deployment.
Satisfied by: Post-market monitoring · Equivalent: NIST AI RMF 1.0 MEASURE 2.4, NIST AI RMF 1.0 MANAGE 4.1, ISO/IEC 42001:2023 Annex A A.6.2.6, NIST AI RMF 1.0 GOVERN 1.5, NIST AI RMF 1.0 MEASURE 3.1, NIST AI RMF 1.0 MEASURE 4.3
When this failed: Zillow Offers iBuying model drift
Art. 73
mandatory
Report serious incidents and malfunctioning to the competent market-surveillance authority.
Satisfied by: Serious-incident reporting · Equivalent: NIST AI RMF 1.0 MANAGE 2.3, NIST AI RMF 1.0 MANAGE 4.3, ISO/IEC 42001:2023 Annex A A.8.4, NIST AI RMF 1.0 GOVERN 4.3