EU AI Act Annex III lists eight high-risk AI use-case categories, including biometrics, education, employment, credit scoring, law enforcement, and justice. See the covered systems, Article 6(3) exception, and the provider and deployer obligations that follow.
An EU Data Act AI compliance checklist covers the parts of Regulation (EU) 2023/2854 that reach an AI deployment: the switching obligations in Chapter VI, the international governmental access safeguards in Article 32, the contractual transparency duty in Article 28, and the connected-product data rules in Chapter II. Each check has an owner, a pass condition, evidence fields, and a boundary line.
This NIS2 AI controls mapping takes the ten measures in Article 21(2) of Directive (EU) 2022/2555 and assigns each one a control point, an owner, a repeatable test, a retained artifact, and a stated boundary on the authenticated path from a user or agent to an LLM. It marks where an HTTP enforcement point contributes directly and where identity, endpoint, continuity and reporting teams stay accountable.
NIS2 AI audit evidence has two customers: a competent authority testing Article 21 measures, and a CSIRT reading an incident notification written against the clocks in Article 23(4). This guide builds one evidence package that serves both, covering population definition, sample binding, integrity, retention, and the boundary where an AI gateway stops contributing.
A NIS2 AI compliance checklist has to grade the ten measures in Article 21(2) against the AI request path, not against a generic security policy. This guide gives each check an owner, a pass condition, an evidence field, and a boundary line, then keeps the 24 hour, 72 hour, and one month reporting clocks from Article 23 attached to the systems that can actually meet them.
A working checklist for businesses running AI over California consumer data before ADMT-specific requirements begin January 1, 2027. Each item names the duty, the concrete action, and the evidence it produces, so the list functions as an audit-readiness pass rather than a statement of intent. Ordered the way a CPPA review moves: scope and identity first, then notice and opt-out, then access, appeal and security.
California finalized its automated decisionmaking technology rules on 23 September 2025. The regulations took effect on 1 January 2026, ADMT obligations attach from 1 April 2027, and the first risk assessments go to the California Privacy Protection Agency by 1 April 2028. This walks the specific evidence a CCPA review asks for when a prompt carrying personal information reaches a model, from pre-use notice through opt-out and appeal, and names which system each artifact has to come from.
A compliance owner tracking California AI law in 2026 has five statutes to sort: SB 1001 bot disclosure, AB 2013 training-data transparency, SB 942 (delayed to August 2, 2026 by AB 853), the CPPA automated-decisionmaking rules under the CCPA, and SB 53 frontier-model safety. This piece separates the obligations that bind you as a deployer from the ones that bind model developers, with effective dates and the primary sources for each.
Compliance teams reach for the GDPR record-keeping playbook when the EU AI Act lands on the legal calendar. The two regimes overlap on data subject rights and personal-data scope. They diverge on the cadence of evidence, the identity of the actor the record describes, and the per-decision trace the AI Act requires. This piece walks through the five axes where the regimes diverge, the record formats each regulator reads, and the architectural changes the AI request path needs before August 2, 2026.
Article 9 of the EU AI Act requires a risk management system for every high-risk AI system, running as a continuous iterative process across the lifecycle. The obligations include risk identification, risk estimation, risk evaluation, and the adoption of risk management measures. The August 2, 2026 deadline applies. Most enterprise AI deployments treat risk management as a documentation exercise that ends at conformity assessment. The Article 9 reading expects an operating system that produces evidence at every decision point.
Article 23 covers importer obligations and Article 24 covers distributor obligations for high-risk AI systems in the EU. The roles get conflated with provider and deployer roles in practice. An importer is the operator that places a high-risk AI system from outside the EU onto the EU market. A distributor is the operator that makes a high-risk AI system available in the EU market without being the importer or the provider. Both have specific verification obligations before the system reaches the deployer. With the August 2, 2026 enforcement date approaching, EU resellers and EU branches of non-EU vendors need to understand which obligations belong to them.
On May 19, 2026, the European Commission published its draft guidelines clarifying which AI systems fall within the high-risk classification under Annex III of the EU AI Act. The guidelines arrive 75 days before the August 2 enforcement date for high-risk obligations. They tighten the criteria for "intended purpose," reshape how deployers and providers classify HR screening, clinical decision support, and fraud detection systems, and accelerate the scope assessment timeline. This article walks through the new criteria, applies them to three concrete enterprise deployments, and identifies the per-decision evidence each will need to produce on demand from August 2 onward.