Regulation

EU AI Act

EU AI Act — principal obligation areas (Chapters II, III, V and IX)

25 requirements · 13 connected unified controls

Open EU AI Act in the map
Version
Regulation (EU) 2024/1689
Published
2024-07-12
Effective
2024-08-01 (staged application 2025-2027)
Amendments
none

Requirements and control mappings

“Full” and “Partial” describe the catalog mapping to a unified control. A partial mapping includes the remaining requirement. These mappings do not establish an organization’s implementation or certification.

EU AI Act

RequirementUnified control and mapping
AIA-Art5Prohibited AI practices
AIA-Art6-7Risk-based classification of high-risk AI systems
AIA-Art9Risk management system (high-risk)
UC-RISK-01 — Establish and maintain a tailored risk management frameworkPartial

Remaining requirement: EU AI Act adds AI-lifecycle-specific continuous risk process and testing

AIA-Art10Data and data governance (high-risk)
AIA-Art11Technical documentation (high-risk)
AIA-Art12Record-keeping / logging (high-risk)
AIA-Art13Transparency and provision of information to deployers (high-risk)
AIA-Art14Human oversight (high-risk)
AIA-Art15Accuracy, robustness and cybersecurity (high-risk)
UC-SDLC-04 — Engineer systems with secure architecture and designPartial

Remaining requirement: AI-specific accuracy metrics and lifecycle-consistent performance require dedicated AI controls

AIA-Art16Obligations of providers of high-risk AI systems
UC-AI-13 — Assign AI value-chain roles and discharge obligationsPartial

Remaining requirement: substantive QMS, conformity-assessment, CE-marking, and EU-database-registration duties are not yet covered by a dedicated unified control - an acknowledged coverage gap in the AI Governance domain

AIA-Art26Obligations of deployers of high-risk AI systems
UC-AI-13 — Assign AI value-chain roles and discharge obligationsPartial

Remaining requirement: operational oversight, monitoring, and log-retention duties evidenced via dedicated controls

AIA-Art50Transparency obligations for certain AI systems (deepfakes, chatbots, emotion recognition)
UC-AI-10 — Meet transparency obligations for AI systemsPartial

Remaining requirement: informing persons exposed to emotion-recognition/biometric-categorisation systems omitted

AIA-Art53Obligations for providers of general-purpose AI (GPAI) models
AIA-Art55Obligations for GPAI models with systemic risk
AIA-Art17Quality management system (providers of high-risk AI systems)
UC-AI-24 — Operate an AI quality management systemPartial

Remaining requirement: risk management, post-market monitoring, serious-incident reporting, and technical-documentation elements of the quality management system are satisfied by their companion controls

AIA-Art18Documentation keeping — 10-year retention of technical documentation, QMS records and conformity documents (providers)
UC-AI-06 — Maintain AI system technical documentationPartial

Remaining requirement: ten-year retention of technical documentation, quality-management records, and conformity documents after the system is placed on the market

AIA-Art19Automatically generated logs — provider retention of high-risk system logs (minimum six months)
AIA-Art20Corrective actions and duty of information for non-conforming high-risk AI systems
UC-AI-11 — Operate AI concern, incident, and external reporting channelsPartial

Remaining requirement: provider-side corrective action (withdrawal, disabling, recall) of non-conforming systems and information to distributors, deployers, and authorities

AIA-Art21-22Cooperation with competent authorities; authorised representatives of non-EU providers
UC-AI-13 — Assign AI value-chain roles and discharge obligationsPartial

Remaining requirement: cooperation with competent authorities on request and appointment of an authorised representative for providers established outside the jurisdiction

AIA-Art23-25Obligations of importers and distributors; responsibilities along the AI value chain
UC-AI-13 — Assign AI value-chain roles and discharge obligationsPartial

Remaining requirement: importer and distributor verification duties and the conditions under which a distributor, importer, or deployer becomes a provider

AIA-Art27Fundamental rights impact assessment for high-risk AI systems (deployers)
AIA-Art43Conformity assessment of high-risk AI systems
UC-AI-13 — Assign AI value-chain roles and discharge obligationsPartial

Remaining requirement: execution of the applicable conformity assessment procedure (internal control or notified body) before placing the system on the market

AIA-Art47-49EU declaration of conformity, CE marking and registration in the EU database
UC-AI-13 — Assign AI value-chain roles and discharge obligationsPartial

Remaining requirement: drawing up the declaration of conformity, affixing the marking, and registering the system in the public database before placing on the market

AIA-Art72Post-market monitoring by providers of high-risk AI systems
UC-AI-08 — Log and monitor AI system behavior in operationPartial

Remaining requirement: a documented post-market monitoring plan, proportionate to the system's risk, that actively collects and analyses lifetime performance data including interaction with other AI systems

AIA-Art73Reporting of serious incidents (providers; deployers inform providers)