This document is under active development and has not been finalised.
Skip to content

Compliance Matrix – Requirements Mapping

Obligations by Risk Level and Role

Minimal Risk

ObligationArticleProviderDeployer
AI LiteracyArt. 4
No further obligations

Limited Risk (Transparency)

ObligationArticleProviderDeployer
AI LiteracyArt. 4
Disclose AI interactionArt. 50(1)
Label synthetic contentArt. 50(2)
Deepfake disclosureArt. 50(4)

High-Risk

ObligationArticleProviderDeployer
AI LiteracyArt. 4
Risk management systemArt. 9✅*
Data GovernanceArt. 10
Technical documentationArt. 11
Record-keepingArt. 12✅ (retention)
Transparency (instructions for use)Art. 13
Human oversightArt. 14✅ (design)✅ (implementation)
Accuracy, robustness, cybersecurityArt. 15
QMSArt. 17
Conformity assessmentArt. 43
EU Declaration of ConformityArt. 47
CE markingArt. 48
Registration (EU database)Art. 49✅**
Post-market monitoringArt. 72
Incident reportingArt. 73

* Deployer: simplified risk management per Art. 26** Deployer: public authorities only

GPAI (Model Providers Only)

ObligationArticleAll GPAI+ Systemic Risk
Technical documentationArt. 53(1)(a)
Info to downstream providersArt. 53(1)(b)
Copyright policyArt. 53(1)(c)
Training data summaryArt. 53(1)(d)
Model evaluationArt. 55(1)(a)
Adversarial testingArt. 55(1)(a)
Risk mitigationArt. 55(1)(b)
Incident reportingArt. 55(1)(c)
Model cybersecurityArt. 55(1)(d)

Documentation licensed under CC BY-NC 4.0 · Code licensed under MIT