1. Define intended purpose
Document exactly what the system is designed to do, for whom, and under what operating conditions.
Compliance begins with classification: confirm whether the technology qualifies as an AI system, define intended purpose, identify your role, then determine the relevant risk and obligation pathway.
Document exactly what the system is designed to do, for whom, and under what operating conditions.
Provider, deployer, importer, distributor and GPAI-model provider roles can trigger different duties.
Check Article 5, Article 6, Annex I, Annex III, Article 50 and GPAI provisions.
Maintain technical documentation, logs, risk records, policies and human-oversight controls where required.
Reassess classification when intended purpose, model capability, deployment context or law changes.
AIACT provides independent research and educational tools. This page is not legal advice. Regulatory status, guidance and implementation dates can change; verify the current official text before relying on it.