AI regulatory compliance needs evidence that a named person or agent reached an approved model, a policy decided the request, and a review can reconstruct that decision. This guide maps EU AI Act, US state, and sector rules to those runtime controls.
EU AI Act Article 73 requires providers of high-risk AI systems to report serious incidents to the relevant market-surveillance authority. This guide explains the Article 3(49) trigger, the 15-day outer limit, the two-day widespread-infringement timeline, the 10-day death timeline, and the evidence a provider needs to investigate and report.
The EU AI Act assigns different obligations to providers and deployers of high-risk AI systems. Article 16 covers provider obligations; Article 26 covers deployer obligations. The split matters because most enterprises operating AI in the EU are deployers, not providers, and the deployer obligations are routinely underestimated. The Digital Omnibus on AI (Regulation (EU) 2026/1744) deferred standalone Annex III high-risk obligations from August 2, 2026 to December 2, 2027, and embedded Annex I systems to August 2, 2028, but the provider-deployer split itself did not change. This article walks the provider-deployer split, the cases that change the assignment, and the architectural artifacts each side needs.
Article 12 of the EU AI Act mandates that high-risk AI systems automatically record events over the system lifetime. The logs must reconstruct what happened, who initiated it, and what data was involved. Penalties reach 15M EUR. Most AI deployments produce zero compliant records today.
Article 13 of the EU AI Act requires providers of high-risk AI systems to design them so deployers can interpret outputs, understand limitations, and exercise human oversight. The mandate takes effect August 2, 2026. Generic model cards fail the test.
Article 19 of the EU AI Act sets the operational floor for log retention from high-risk AI systems at six months and specifies what the automatically generated logs must contain. The mandate takes effect August 2, 2026. Application logs fail the structural test.
Article 26 of the EU AI Act puts operational obligations on the deployer of a high-risk AI system. The deployer must monitor operation, suspend use under specific risk conditions, keep automatically generated logs, and inform the provider and authorities. The mandate takes effect August 2, 2026.
Annex III of the EU AI Act lists the eight categories of AI systems classified as high-risk. Inclusion in Annex III triggers the full obligations of Articles 8 to 27 from August 2, 2026. Most enterprise teams are inside the scope without realizing it.
Article 6 of the EU AI Act establishes a two-branch test for classifying an AI system as high-risk. Branch one covers safety components of regulated products. Branch two covers the Annex III use cases. The classification triggers the full operational regime from August 2, 2026.
EU AI Act compliance breaks into six operational workstreams: scope classification, technical documentation, conformity assessment, runtime evidence, deployer monitoring, and incident reporting. The mandate takes effect August 2, 2026. Most organizations are running three of the six and missing the rest.
A 23-item operational checklist for EU AI Act high-risk compliance, organized across scope, documentation, evidence, monitoring, and incident reporting. The mandate takes effect August 2, 2026. Items 12 to 18 are where most deployments fail.
GDPR governs the processing of personal data. The EU AI Act governs the operation of AI systems. The two regimes overlap on automated decision-making and divergent on per-decision evidence. GDPR records describe what data is processed. AI Act records describe what an AI system did with a specific request.