TwinEthosRequest access

Catalog

EU AI Act

European Commission / national market surveillance authorities · pack 0.1.2 · verified against the official source as of 2026-09-26.

Binding law — not yet in force or stayed

High-risk AI training data must be governed and examined for bias (EU AI Act Art. 10)

Under EU AI Act Article 10(2), training, validation, and testing data sets for high-risk AI systems must be subject to data governance and management practices appropriate to the intended purpose, covering: design choices; data collection processes and data origin (and, for personal data, the original collection purpose); data-preparation operations (annotation, labelling, cleaning, updating, enrichment, aggregation); assumptions about what the data measures and represents; assessment of the availability, quantity, and suitability of data sets; examination for possible biases likely to affect health and safety, negatively impact fundamental rights, or lead to prohibited discrimination — especially where outputs feed future inputs; appropriate measures to detect, prevent, and mitigate identified biases; and identification of data gaps or shortcomings and how they are addressed. Data sets must be relevant, sufficiently representative, and to the best extent possible error-free and complete. Detect a high-risk AI training pipeline with no documented data-governance practice or bias examination/mitigation.

eu-ai-act.art10.data-governance-bias · Article 10(2) · official source · applies from 2027-12-02 · jurisdictions: EU

Binding law — not yet in force or stayed

High-risk AI systems must automatically log events for traceability (EU AI Act Art. 12)

Under EU AI Act Article 12, high-risk AI systems must technically allow the automatic recording of events (logs) over the lifetime of the system, with logging capabilities that ensure a level of traceability appropriate to the intended purpose — specifically enabling identification of situations that may present a risk under Art. 79(1) or a substantial modification, facilitating post-market monitoring (Art. 72), and monitoring the operation of high-risk systems under Art. 26(5). For remote biometric identification systems (Annex III point 1(a)) logs must at minimum record each use period, the reference database, matched input data, and the identity of the natural persons verifying results. Providers must retain these logs at least six months (Art. 19); deployers likewise (Art. 26(6)). Detect a high-risk AI decision path with no automatic event logging or retention.

eu-ai-act.art12.record-keeping · Article 12 · official source · applies from 2027-12-02 · jurisdictions: EU

Binding law — not yet in force or stayed

High-risk AI systems must be designed for effective human oversight with override and stop (EU AI Act Art. 14)

Under EU AI Act Article 14, high-risk AI systems must be designed and developed — including with appropriate human-machine interface tools — so they can be effectively overseen by natural persons while in use, to prevent or minimise risks to health, safety, or fundamental rights. Oversight measures must be commensurate with the risk, autonomy, and context, built into the system by the provider and/or implementable by the deployer. Assigned overseers must be enabled to: understand the system's capacities and limitations and monitor for anomalies; remain aware of automation bias (over-reliance on outputs); correctly interpret outputs; decide not to use the system or to disregard, override, or reverse its output; and intervene or interrupt via a 'stop' button or equivalent bringing the system to a safe halt. For remote biometric identification (Annex III 1(a)), no action may be taken on an identification unless separately verified by at least two competent natural persons. Detect a high-risk AI decision path with no human-oversight affordance, no override/stop capability, or no assigned competent overseer.

eu-ai-act.art14.human-oversight · Article 14 · official source · applies from 2027-12-02 · jurisdictions: EU

Binding law — not yet in force or stayed

High-risk AI systems must be accurate, robust, and secure against AI-specific attacks (EU AI Act Art. 15)

Under EU AI Act Article 15, high-risk AI systems must be designed to achieve an appropriate level of accuracy, robustness, and cybersecurity and to perform consistently in those respects throughout their lifecycle, with accuracy levels and metrics declared in the instructions for use. They must be as resilient as possible to errors, faults, or inconsistencies — potentially via technical redundancy such as backup or fail-safe plans — and systems that continue to learn after deployment must be developed to eliminate or reduce the risk of biased outputs influencing future inputs (feedback loops), with such loops duly mitigated. They must also be resilient to unauthorised third parties altering their use, outputs, or performance, with technical solutions addressing AI-specific vulnerabilities including training-data poisoning, model poisoning of pre-trained components, adversarial examples / model evasion, confidentiality attacks, and model flaws. Detect a high-risk AI path with no declared accuracy metrics, no robustness/fail-safe provision, unmitigated feedback loops, or no AI-specific security controls.

eu-ai-act.art15.accuracy-robustness-cybersecurity · Article 15 · official source · applies from 2027-12-02 · jurisdictions: EU

Binding law — not yet in force or stayed

Deployers must inform people they are subject to a high-risk AI decision (EU AI Act Art. 26(11))

Under EU AI Act Article 26(11), deployers of Annex III high-risk AI systems that make decisions or assist in making decisions related to natural persons must inform those persons that they are subject to the use of the high-risk AI system (without prejudice to the Art. 50 transparency duties; for law-enforcement uses, Art. 13 of Directive (EU) 2016/680 applies instead). Related deployer duties: use the system per the instructions for use (26(1)), assign competent human oversight (26(2)), ensure input data relevance where the deployer controls it (26(4)), monitor operation and suspend + notify on risk or serious incident (26(5)), retain logs for at least six months (26(6)), and inform workers' representatives and affected workers before workplace deployment (26(7)). Detect an Annex III high-risk decision path affecting individuals with no notice to those individuals.

eu-ai-act.art26.inform-affected-persons · Article 26(11) · official source · applies from 2027-12-02 · jurisdictions: EU

Binding law — not yet in force or stayed

Public-sector and essential-service deployers must run a fundamental rights impact assessment (EU AI Act Art. 27)

Under EU AI Act Article 27(1), before deploying an Annex III high-risk AI system, deployers that are bodies governed by public law or private entities providing public services — and deployers of creditworthiness/credit-scoring and life/health insurance risk-assessment systems (Annex III points 5(b) and (c)) — must perform a fundamental rights impact assessment (FRIA) covering: the deployer's processes in which the system will be used; the period and frequency of intended use; the categories of natural persons and groups likely to be affected; the specific risks of harm to those persons; the implementation of human oversight measures per the instructions for use; and the measures to take if those risks materialise, including internal governance arrangements and complaint mechanisms. The assessment applies to first use, may reuse prior assessments in similar cases, must be updated when elements change, and its results must be notified to the market surveillance authority. Where a GDPR Art. 35 DPIA already covers elements, the FRIA may cross-reference it. Detect a covered high-risk deployment with no FRIA record or notification.

eu-ai-act.art27.fria · Article 27(1) · official source · applies from 2027-12-02 · jurisdictions: EU

Binding law — in force

AI must not categorise people by sensitive traits from biometric data

Using biometric data to deduce or infer sensitive traits (race, political opinions, trade-union membership, religious/philosophical beliefs, sex life, sexual orientation) is prohibited. Detect inference of these categories from biometric input.

eu-ai-act.art5.biometric-categorisation-sensitive-traits · Article 5(1)(g) · official source · jurisdictions: EU

Binding law — in force

AI must not infer emotions in workplace or education settings

Placing on the market or using AI to infer the emotions of people in workplace or education contexts is prohibited, except for medical or safety purposes. Detect emotion-inference models invoked on paths serving workplace or education features.

eu-ai-act.art5.emotion-recognition-workplace-education · Article 5(1)(f) · official source · jurisdictions: EU

Binding law — not yet in force or stayed

AI generating non-consensual intimate imagery or CSAM is prohibited (EU AI Act Art. 5(1)(ba),(bb))

Regulation (EU) 2026/1744 inserted two new prohibited practices into EU AI Act Article 5(1). Point (ba) prohibits placing on the market, putting into service, or using an AI system that generates or manipulates realistic images, video, audio, or similar material of an identifiable natural person's intimate parts, or of an identifiable person engaged in sexually explicit activities, without that person's freely-given, specific, informed, unambiguous and explicit consent. Point (bb) prohibits the same for material or performance within the meaning of Article 2(c) and (e) of Directive 2011/93/EU (child sexual abuse material), except where a 'without right' defence applies under national law. Article 5(1a) sets the safeguards test: placing on the market or putting into service is prohibited where such generation is the system's intended purpose, OR where the design, training, architecture, capabilities, or user-facing functionality make it a reasonably foreseeable and reproducible outcome without significant technical modification AND the system lacks reasonable and adequate technical safety measures to reliably prevent it (accounting for foreseeable misuse) and to correct observed or reported misuse. USE is prohibited where the deployer uses the system for that purpose. Art. 5(1b) clarifies that manipulation not increasing exposure of intimate parts or altering the nature of depicted sexually explicit activity is not 'manipulation'. Highest penalty tier (EUR 35m / 7%). Detect an image/video/audio generation path with no safeguards reliably preventing non-consensual intimate imagery or CSAM, and no misuse-correction mechanism.

eu-ai-act.art5.nonconsensual-intimate-and-csam · Article 5(1)(ba),(bb) [as inserted by Reg. (EU) 2026/1744] · official source · applies from 2026-12-02 · jurisdictions: EU

Binding law — in force

Building facial-recognition databases by untargeted scraping is prohibited (EU AI Act Art. 5(1)(e))

Under EU AI Act Article 5(1)(e), it is a prohibited AI practice to place on the market, put into service for this specific purpose, or use AI systems that create or expand facial recognition databases through the untargeted scraping of facial images from the internet or CCTV footage. This is an outright prohibition — not a transparency or risk-management duty — and carries the Regulation's highest penalty tier (up to EUR 35,000,000 or 7% of worldwide annual turnover). Detect any ingestion pipeline that bulk-collects facial images from web sources or CCTV into a face-recognition/embedding index without targeting.

eu-ai-act.art5.untargeted-facial-scraping · Article 5(1)(e) · official source · jurisdictions: EU

Binding law — in force

AI chat systems must disclose they are AI at first interaction

Any system that interacts directly with a person via AI (a chatbot, a conversational agent) must inform the person they are interacting with an AI system, clearly and at the latest at the first interaction — unless it is obvious to a reasonable person, or the use is legally authorised for detecting or investigating crime.

eu-ai-act.art50.chatbot-disclosure · Article 50(1) · official source · jurisdictions: EU

Binding law — in force

Deepfake content must be disclosed as artificially generated

Deployers publishing deepfake image, audio, or video must disclose that it was artificially generated or manipulated. Detect deepfake generation/publishing paths with no disclosure attached.

eu-ai-act.art50.deepfake-disclosure · Article 50(4) · official source · jurisdictions: EU

Binding law — in force

Deployers of emotion-recognition/biometric-categorisation systems must notify exposed persons (EU AI Act Art. 50(3))

Under EU AI Act Article 50(3), deployers of an emotion recognition system or a biometric categorisation system must inform the natural persons exposed to it of the operation of the system, and process personal data per GDPR/EUDPR/LED. This is a distinct transparency duty for PERMITTED deployments (separate from the Article 5 prohibitions on certain emotion/biometric uses). Exception: systems permitted by law to detect/prevent/investigate criminal offences with safeguards. Detect an emotion-recognition or biometric-categorisation deployment with no exposure notice to affected persons.

eu-ai-act.art50.emotion-biometric-notice · Article 50(3) · official source · jurisdictions: EU

Binding law — in force

AI-generated public-interest text must be disclosed unless under human editorial control (EU AI Act Art. 50(4))

Under EU AI Act Article 50(4) (second subparagraph), deployers of an AI system that generates or manipulates TEXT published to inform the public on matters of public interest must disclose that the text has been artificially generated or manipulated. Distinct from the deepfake (image/audio/video) duty. Exceptions: law-enforcement use, OR where the AI-generated content has undergone human review / editorial control and a natural or legal person holds editorial responsibility for the publication. Detect an automated publishing path emitting public-interest text with no AI-generation disclosure and no human-editorial-control marker.

eu-ai-act.art50.public-interest-text-disclosure · Article 50(4) subpara 2 (public-interest text) · official source · jurisdictions: EU

Binding law — in force

Synthetic AI output must be machine-readably marked as artificial

Providers of systems generating synthetic audio, image, video, or text must mark outputs in a machine-readable way (e.g. C2PA, watermarking, provenance metadata) so they are detectable as AI-generated. Detect synthetic-content generation whose output path emits no provenance marking.

eu-ai-act.art50.synthetic-content-machine-marking · Article 50(2) · official source · jurisdictions: EU

Binding law — not yet in force or stayed

Affected persons can demand a meaningful explanation of a high-risk AI decision (EU AI Act Art. 86)

Under EU AI Act Article 86, any affected person subject to a decision taken by a deployer on the basis of the output of an Annex III high-risk AI system (except Annex III point 2, critical infrastructure) that produces legal effects or similarly significantly affects them in a way they consider adverse to their health, safety, or fundamental rights has the right to obtain from the DEPLOYER clear and meaningful explanations of the role of the AI system in the decision-making procedure and the main elements of the decision taken. The right does not apply where Union or national law provides exceptions/restrictions, and applies only to the extent the right is not otherwise provided under Union law (notably GDPR Art. 22). The deployer is the sole interlocutor even where the model came from a third party — so the practical burden is reconstructing, after the fact, what the model actually did at decision time. Detect an Annex III high-risk decision path with no capability to produce a per-decision explanation on request (no decision-time model/version/feature record, no explanation surface).

eu-ai-act.art86.right-to-explanation · Article 86 · official source · applies from 2026-08-02 · jurisdictions: EU