The obligations that attach to building or deploying an AI system. Governance duties, documentation, transparency and classification, most of which land on legal and compliance with security holding the evidence.
What we track
EU AI Act
EU. Prohibited practices, high-risk classification, general purpose model duties, and the phased application date behind each.
Transparency and labelling duties
EU. Disclosure obligations for generated and manipulated content, enforceable from 2 August 2026.
High-risk classification in practice
EU. Where classification is biting first, including credit scoring and other decisions taken about people.
ISO/IEC 42001
International. AI management systems, and the sectors where certification is becoming a procurement expectation.
Data protection authority guidance
EU and UK. Web scraping, training data, and the lawful basis questions attached to both.
National and sector rules
UK, US and Singapore. Sector regulators moving before any general statute does.
Who is in scope
The AI Act allocates duties by role. Providers develop a system or have one developed and place it on the market under their own name. Deployers use a system under their own authority. Importers and distributors owe duties of their own, and an authorised representative is required for providers outside the Union.
Obligation weight follows risk classification, and organisation size barely features. A small company deploying a high-risk system owes more than a large one deploying a minimal-risk one, which is the opposite of how most compliance regimes are shaped.
Where the deadlines fall
The AI Act applies in phases. Prohibited practices came first, then obligations on general purpose models, then transparency duties, with high-risk obligations arriving later and the heaviest ones later still. Transparency and deepfake labelling duties became enforceable on 2 August 2026.
Because the phases attach to different articles, an organisation can be compliant with the parts in force and unprepared for the parts arriving next year. The Radar’s regulatory timeline holds the phases so the gap is visible before it is urgent.
Where organisations get caught
Role. Provider and deployer carry different obligations, and most organisations are deployers who assume that buying a system puts them outside the regime. Fine-tuning a model, or putting your own name on a system, can move you into the provider role without anyone deciding to.
Inventory. Obligations attach per system, so an organisation that cannot list its AI systems cannot demonstrate compliance for any of them. Shadow deployment through software-as-a-service features is the usual reason the list is wrong, because nobody procured an AI system, they procured a customer service tool that grew one.
Classification creep. High-risk classification follows the use case, so the same model is high-risk in a hiring decision and minimal-risk in a drafting assistant. Governance that classifies the technology instead of the use will produce the wrong answer.
Questions worth asking now
- Can we list every AI system in use, including features inside products we already buy?
- For each one, are we the provider or the deployer, and would a regulator agree?
- Which of them touch decisions about people, and have we classified those?
- Has anything we fine-tuned or rebranded moved us into provider obligations?
- Where we generate or manipulate content, is it disclosed as the transparency duties require?
- Who owns AI governance, and do they have visibility of procurement?
Related domains
AI security covers securing the systems this domain governs. Data security and privacy covers training data and lawful basis. Robotics and autonomous systems covers AI as a safety component.