Documentation — EU obligations
Documentation of the obligations, step by step. Every step has a control point, every claim an article, and the chain carries hashes so the work can be shown afterwards.
Step by step
- 1. Write down the assessment with article, role and date on every row. Can be shown: the list, with date and owner.
- 2. Link every claim to the node it rests on, not to a summary. Can be shown: the role choice with one sentence on why.
- 3. Store hash and reading date together with the text. Can be shown: the article rows with address, hash and reading date.
- 4. Mark what is your assessment and what is the source's wording. Can be shown: the gaps and what was decided about them.
- 5. Put the document where the reviewer finds it without asking. Can be shown: the next check date and who owns it.
Audit chain
- AI Act — 16: Obligations of providers of high-risk AI systems — d761b4ad84667a7a
- AI Act — 9: Risk management system — 91e28ba13e856d01
- AI Act — 10: Data and data governance — 34cab46756a62c48
- AI Act — 11: Technical documentation — 8f24e040f4a047ed
- AI Act — 12: Record-keeping — fbda0e09e1628ede
- AI Act — 17: Quality management system — b27b9316f51df657
- AI Act — 43: Conformity assessment — 64c11ce3ac8a8dce
- AI Act — 72: Post-market monitoring by providers and post-market monitoring plan for high-risk AI systems — 02b776ab8e746a88
What forces a redo
- The node hash changes — the text behind the row is no longer the same.
- The reading date moves forward — the row has been re-read against the source.
- A timeline passes — the requirement starts to apply or tightens.
As data
- The same node as data: add ?format=json to the address, or ?format=agent for receipt and dependencies.
Roles
Articles
- AI Act — 16: Obligations of providers of high-risk AI systems
- AI Act — 9: Risk management system
- AI Act — 10: Data and data governance
- AI Act — 11: Technical documentation
- AI Act — 12: Record-keeping
- AI Act — 17: Quality management system
- AI Act — 43: Conformity assessment
- AI Act — 72: Post-market monitoring by providers and post-market monitoring plan for high-risk AI systems
- AI Act — 73: Reporting of serious incidents
- AI Act — 26: Obligations of deployers of high-risk AI systems
- AI Act — 27: Fundamental rights impact assessment for high-risk AI systems
- AI Act — 23: Obligations of importers
- AI Act — 24: Obligations of distributors
- AI Act — 53: Obligations for providers of general-purpose AI models
- AI Act — 55: Obligations of providers of general-purpose AI models with systemic risk
- GDPR — 24: Responsibility of the controller
- GDPR — 25: Data protection by design and by default
- GDPR — 30: Records of processing activities
- GDPR — 32: Security of processing
- GDPR — 33: Notification of a personal data breach to the supervisory authority
- GDPR — 35: Data protection impact assessment
- GDPR — 28: Processor
- NIS2 — 21: Cybersecurity risk-management measures
- NIS2 — 23: Reporting obligations
Relations
Metadata
- Acts
- AI Act, GDPR, NIS2, DSA, Dataförordningen, DGA
- Articles
- 32
- Reading date
- 2026-08-31
- Freshness
- 74/100
- Hash
- ae8f9416aa756f6e
- Corpus version
- legal-2026-08-25
- Next check
- —
Next step
Three ways to put the register to work in your own practice.
Start with your task
Litigation
Find support in a judgment
Search guiding decisions, see what became final and follow changes in the law.
In-house, deals
Map the rules in a transaction
Move from theme to act and on to the article that carries the duty.
Compliance
Assess the risk in a process
Risk scoring per legal area, with the sources behind every score.