EU AI Act · Articles 9–17 · Obligation Management

EU AI Act Obligation Matrix — know exactly what the law requires.

Every obligation that applies to your AI systems — derived from your risk classification, mapped to your roles, and tracked to completion.

The EU AI Act imposes different obligations depending on how an AI system is classified. EAB translates your screening result into a concrete, actionable set of requirements — with nothing left to interpretation.

113 operative articles mapped Derived from screening result Role-assigned per obligation
Articles covered
113
Every operative article of Regulation (EU) 2024/1689 mapped to obligations.
Risk profiles
4
Unacceptable, High Risk, Limited, Minimal — each with its own obligation set.
Manual interpretation
Zero
Obligations are derived algorithmically from the screening result, not filled in by hand.
Legal source
1
CELEX 32024R1689 — version-stamped, tracked, and re-screened when it changes.
The concept

Your screening result becomes your compliance roadmap.

When a supervisor screens an AI system and assigns a risk level, EAB immediately derives the full set of applicable obligations from the regulation. These are not generic checklists — they are tied to the specific articles that apply to your system's profile.

Each obligation carries the article reference, the responsible role, the evidence required, and a status that updates as your team works through it. When the legal source changes, the obligation set is re-derived automatically — so you never work from an outdated baseline.

The result is a living document: not a spreadsheet you maintain, but a structured record that reflects your actual compliance state at any point in time — and that an auditor can inspect without any preparation from your side.

Obligation Categories
  • Art. 9Risk Management System
  • Art. 10Data & Data Governance
  • Art. 11Technical Documentation
  • Art. 13Transparency & User Information
  • Art. 14Human Oversight Provisions
  • Art. 16Provider Obligations
  • Art. 17Quality Management System
  • Art. 43Conformity Assessment
Why it matters

“An audit doesn’t ask whether you knew. It asks whether you can show what you did — and when.”

EAB Design Principle · Reconstructability
What's tracked

Obligations, per system and per role.

Six obligation areas cover the full high-risk compliance surface. Each is assigned to a role, linked to evidence requirements, and tracked independently per AI system.

Art. 9

Risk Management System

A documented, continuous process for identifying, analyzing, and mitigating foreseeable risks. EAB structures the required stages and attaches evidence to each cycle.

Art. 10–11

Data & Technical Documentation

Training data governance and the full technical record — architecture, performance metrics, intended use, and known limitations — collected during the screening workflow, not retroactively.

Art. 13

Transparency

Instructions for use, disclosure to affected parties, and capability limitations — structured to meet the article requirements and exportable for inclusion in any user-facing documentation.

Art. 14

Human Oversight Provisions

The measures that enable humans to understand, monitor, and intervene in the AI system's operation. EAB maps these to named roles and documents what each oversight measure consists of.

Art. 17

Quality Management

Policies, procedures, and review cycles required of providers. EAB tracks the QMS obligation status per system and flags gaps before a conformity assessment is due.

Art. 43

Conformity Assessment

For Annex III high-risk systems: the path to a conformity declaration. EAB tracks the required documentation, notified body involvement, and the version of the standard applied.

In practice

Live status across your entire AI inventory.

Per-system obligation view
  • Risk classification & applicable articles
  • Obligation status: pending / in progress / done
  • Evidence attached per obligation
  • Responsible role assigned
  • Legal version in force at last update
  • Re-screening flag if legal source changed

One view, every system, no spreadsheet.

As soon as a system is classified, its obligation profile is live. Each responsible role sees exactly what they must do, what evidence is required, and whether it has been provided — without any manual coordination.

Compliance managers see the status across the entire system inventory at a glance: filtered by risk level, role, module, or obligation area. When legal sources change, the affected systems are flagged automatically and the obligation set is re-derived from the new version.

Auditors get a read-only view of the same data, frozen at any point in time. No export needed. No preparation required from your team.

Get started

Stop tracking obligations in spreadsheets.

EAB derives your obligation set from your screening result and keeps it current. Available in Small Business and Enterprise tiers.

EU-hosted · Anchored to CELEX 32024R1689

Get in Touch
Request More Information

Tell us about your organization and what you’re looking to address. We’ll follow up with the relevant information.