Map the provider role and the practical work associated with developing or placing an AI system on the market.
Inventory and intended purpose
Record each system’s purpose, release owner, model dependencies, users and distribution path. This creates a basis for identifying potentially applicable provisions.
If the system is high-risk
Provider duties can include risk management, data governance, technical documentation, logging capability, instructions for use, human oversight design, accuracy, robustness and cybersecurity, along with conformity processes. The specific route depends on the system.
Review high-risk obligations ↗After release
Relevant high-risk providers should plan for quality management, post-market monitoring and incident handling under the applicable provisions. Assign owners and retain evidence of decisions.
This guide is an orientation, not a legal determination. Check the current legal text and official implementation guidance for your system.
Read the AI Act ↗European Commission overview ↗