EU obligations as open data
The same act places different duties on different roles. This surface makes that searchable: each row is one duty, tied to a role, an act and an article — with the address where the requirement is published.
What the surface gives out
- The duty in short form, and the role it reaches.
- The act with its CELEX identifier and the article carrying the duty.
- Canonical address, hash and reading date per row.
How to fetch it
- The address is /api/public/v1/open/eu/obligations and answers without a key.
- Filter by role or act, or fetch the whole list.
- ETag, Last-Modified, 304 on unchanged content and a next-check date.
How it is used
- Build a requirement list for the role your company actually holds.
- Review a supplier against the duties their role carries.
- Show in a product which articles govern a given feature.
What the usage shows
- NovaCopilot is used by professional lawyers and compliance teams in 17 countries.
- The agent API is used in product evaluations by international teams.
- AI Act articles are read in sequence — a clear sign of regulatory use.
Professional roles on this surface
Every row is its own node with source, reading date, hash and the same answer as data.
Workflows on this surface
Every row is its own node with source, reading date, hash and the same answer as data.
The articles the surface touches
Every row is its own node with source, reading date, hash and the same answer as data.
- AI Act — 16: Obligations of providers of high-risk AI systems
- AI Act — 9: Risk management system
- AI Act — 10: Data and data governance
- AI Act — 11: Technical documentation
- AI Act — 12: Record-keeping
- AI Act — 17: Quality management system
- AI Act — 43: Conformity assessment
- AI Act — 72: Post-market monitoring by providers and post-market monitoring plan for high-risk AI systems
- AI Act — 73: Reporting of serious incidents
- AI Act — 26: Obligations of deployers of high-risk AI systems
- AI Act — 27: Fundamental rights impact assessment for high-risk AI systems
- AI Act — 23: Obligations of importers
- AI Act — 24: Obligations of distributors
- AI Act — 53: Obligations for providers of general-purpose AI models
- AI Act — 55: Obligations of providers of general-purpose AI models with systemic risk
- GDPR — 24: Responsibility of the controller
- GDPR — 25: Data protection by design and by default
- GDPR — 30: Records of processing activities
- GDPR — 32: Security of processing
- GDPR — 33: Notification of a personal data breach to the supervisory authority
- GDPR — 35: Data protection impact assessment
- GDPR — 28: Processor
- NIS2 — 21: Cybersecurity risk-management measures
- NIS2 — 23: Reporting obligations
- NIS2 — 20: Governance
- DSA — 16: Notice and action mechanisms
- DSA — 17: Statement of reasons
- DSA — 34: Risk assessment
- DSA — 35: Mitigation of risks
- Dataförordningen — 4: The rights and obligations of users and data holders with regard to access, use and making available product data and related service data
- Dataförordningen — 23: Removing obstacles to effective switching
- DGA — 12: Conditions for providing data intermediation services
FAQ
- Are the rows an interpretation?
- A row points out which article carries the duty. The assessment in your case is yours to make, with the article in front of you.
- Which roles exist?
- The roles the acts themselves use — for example provider, deployer, importer, distributor, controller and processor.
- May we build our own service on the surface?
- Yes, commercially and free of charge. The only thing not permitted is reselling the dataset as such.
Next step
Three ways to put the register to work in your own practice.
Start with your task
Litigation
Find support in a judgment
Search guiding decisions, see what became final and follow changes in the law.
In-house, deals
Map the rules in a transaction
Move from theme to act and on to the article that carries the duty.
Compliance
Assess the risk in a process
Risk scoring per legal area, with the sources behind every score.