ARE YOU ACTUALLY THE PROVIDER?
Start with the Regulation’s operator definitions and the facts of the system. Branding, development, market placement, substantial modification and intended-purpose changes can matter to the role analysis.
Provider obligations are not a one-page checklist. They begin with the actual system and role, then move through classification, evidence, conformity and continuing lifecycle duties. TA-14 turns that obligation map into an attributable operating record.
Use the official Regulation as the controlling source. Provider duties vary by system and route; high-risk provider requirements span Articles 8–25 with additional conformity, registration, post-market and incident provisions elsewhere in the Regulation.
Start with the actual system, role, use case and evidence boundary. The same regulation can produce different obligations for different actors and systems.
Start with the Regulation’s operator definitions and the facts of the system. Branding, development, market placement, substantial modification and intended-purpose changes can matter to the role analysis.
Screen prohibited practices, high-risk pathways, transparency duties, GPAI involvement and other applicable routes before assuming every provider carries the same obligation set.
For high-risk systems, provider work can include risk management, data governance, technical documentation, logging capability, instructions, oversight design, performance controls and quality management.
Conformity, registration, documentation retention, corrective action, post-market monitoring, serious-incident handling and material-change review make provider governance a lifecycle responsibility.
The goal is not merely to reach an answer. It is to preserve what facts, evidence, scope and limitations supported that answer at that time.
Bind the obligation analysis to the actual system and version instead of treating a company-wide label as proof of role.
Connect each relevant requirement to the document, test, log, control, accountable owner and source needed to support it.
Where applicable, preserve the assessment route, declaration, registration, marking, instructions and evidence package supporting market placement or service entry.
Material changes, incidents, drift, new intended purposes and new evidence can change the prior position. Preserve the chronology and determine what must be re-examined.
Choose the smallest operating tier that fits the portfolio today. Upgrade when system count, team size or governance scope actually requires it.
Keep a living system-level evidence record with obligations, gaps, versions and revalidation state.
START EVIDENCE PASSPORT →Coordinate evidence, owners, documentation, incidents and team compliance work in one governed workspace.
START COMPLIANCE WORKSPACE →Operate broader high-risk, GPAI, FRIA, post-market and material-change governance across a growing portfolio.
START GOVERNANCE PRO →Run institutional governance with expanded users, authority workflows, examiner rooms and portfolio reporting.
START INSTITUTION →Use the free classifier to establish the system, intended purpose, possible actor role, EU exposure and unresolved facts. When continuing evidence infrastructure is needed, paid access begins at $19 per month. Independent human readiness review remains a separate service.
The Regulation defines a provider by the legal and factual relationship to development and placing an AI system or GPAI model on the market or putting an AI system into service under its own name or trademark. Specific facts should be checked against the current legal text.
No. Duties depend on matters including the system classification, intended purpose, whether the system is high-risk, transparency obligations, GPAI status and the organization’s actual operator role.
The high-risk framework includes risk management, data and data governance, technical documentation, recordkeeping capability, transparency and instructions, human oversight design, accuracy/robustness/cybersecurity and quality-management obligations, alongside conformity and lifecycle duties.
For high-risk AI systems, Article 11 requires technical documentation before market placement or putting into service and requires it to be kept up to date.
No. The Regulation includes continuing duties such as post-market monitoring, corrective action and serious-incident processes, subject to the applicable system and role.
No. TA-14 can help structure applicability, evidence, gaps, provenance, change and revalidation records. It does not turn a software subscription into legal advice, certification, conformity assessment or regulatory approval.
TA-14 Exchange Activity
Live cumulative activity recorded across the public Exchange surface.
···
Visitors
Recorded public visitors
···
Page Views
Recorded Exchange views