AI Act Obligations for Operators

A complete, article-by-article reference for AI Act operators — generated from the RuleMesh knowledge graph (CELEX 32024R1689). Covers all 1 obligation paragraph sourced from the regulation, with relevant annexes and GDPR cross-references quoted verbatim.

CELEX 32024R1689·1 obligation paragraphs·Most obligations effective 2026-08-02

This page is generated from the RuleMesh knowledge graph — every obligation, annex block, and cross-reference is pulled from the structured graph representation of CELEX 32024R1689, not recalled from memory.

update

These deadlines have been amended. The Digital Omnibus on AI, Regulation (EU) 2026/1744, has been in force since 27 July 2026. Stand-alone high-risk deadlines (Annex III) moved to 2 December 2027 and product-embedded high-risk (Annex I) to 2 August 2028, and two new Article 5 prohibitions start 2 December 2026. Article 50 transparency is unchanged at 2 August 2026. The high-risk dates quoted below still show the original Regulation 2024/1689 values and are being regenerated; where they differ, take the dates in this notice. Read the briefing.

Regulation (EU) 2024/1689 — CELEX 32024R1689

This page is generated from the RuleMesh knowledge graph — every obligation, annex block, and cross-reference below is pulled from the structured graph representation of the regulation, not recalled from memory.


Who is an operator?

An operator, in the AI Act sense, is an umbrella term encompassing any natural or legal person involved in the AI value chain in a regulated capacity — specifically: providers, product manufacturers, deployers, authorised representatives, importers, and distributors — each bearing distinct obligations depending on their role.

1 obligation paragraph in the AI Act is addressed to the Operator role. Most obligations for high-risk AI systems apply from 2 August 2026; obligations for general-purpose AI model providers and the AI Act's governance bodies apply from 2 August 2025.


Jump to an article


Article 74 - Market surveillance and control of AI systems in the Union market

Art. 74(1). This paragraph extends the application of the EU Market Surveillance Regulation (2019/1020) to AI systems covered by the AI Act, ensuring that references to 'economic operators' and 'products' in that regulation are interpreted to include all AI system operators and AI systems within the AI Act's scope.

chevron_rightSource text

Source text: “Regulation (EU) 2019/1020 shall apply to AI systems covered by this Regulation. For the purposes of the effective enforcement of this Regulation:”

In practice: Operators of AI systems should familiarise themselves with Regulation (EU) 2019/1020 obligations (e.g., cooperation with market surveillance authorities, product traceability) as these now apply to them. Map your AI system supply chain roles (provider, deployer, importer, distributor) to the economic operator definitions.


Bridge to product

Across the AI Act, the obligations that touch personal data converge on the same engineering controls GDPR already requires — and RuleMesh ships those as a ready-to-implement Jira backlog today.

  • Risk management (AI Act Art. 9) ↔ GDPR Art. 32 (technical & organisational measures)
  • Data governance / bias detection (Art. 10) ↔ GDPR Art. 9 (special categories) + Art. 32
  • Automated logging (Art. 12) ↔ GDPR Art. 32 (audit trail / breach detection)
  • Human oversight (Art. 14) ↔ GDPR Art. 22 (automated-decision safeguards)
  • Deployer DPIA / FRIA (Arts. 26–27) ↔ GDPR Art. 35 (data protection impact assessment)

RuleMesh ships the EU AI Act as engineered rules, alongside GDPR — each obligation traced from the article that requires it to the control that addresses it, the configuration that implements it, and the evidence an auditor expects. Where the AI Act routes to GDPR articles, those modules are already in place. RuleMesh does not make you compliant; it gives engineers and AI agents the specification to implement against, and auditors the chain to verify.

Explore GDPR control modules in RuleMesh →


Frequently asked questions

Who is an operator under the EU AI Act?

An operator, in the AI Act sense, is an umbrella term encompassing any natural or legal person involved in the AI value chain in a regulated capacity — specifically: providers, product manufacturers, deployers, authorised representatives, importers, and distributors — each bearing distinct obligations depending on their role. (Source: AI Act definitions, CELEX 32024R1689.)

How many obligations does the AI Act place on operators?

The RuleMesh knowledge graph identifies 1 obligation paragraph addressed to the Operator role, across Article 74.

When do AI Act operators obligations apply?

Most obligations relating to high-risk AI systems apply from 2 August 2026. Obligations for providers of general-purpose AI models and the AI Act's governance framework apply from 2 August 2025, and the Article 5 prohibitions applied from 2 February 2025.

Do the AI Act operators obligations overlap with GDPR?

Yes. The AI Act repeatedly references specific GDPR articles and does not override GDPR — for example special-category data for bias detection (GDPR Art. 9), data protection impact assessments (GDPR Art. 35), and the technical and organisational measures of GDPR Art. 32. The two regulations require the same engineering controls.



Source data: RuleMesh knowledge graph — Fuseki legalrules dataset, CELEX 32024R1689 (EU AI Act), with cross-references resolved into CELEX 32016R0679 (GDPR). This page is education and reference only — it is not legal advice. RuleMesh's product offer is GDPR control modules in Jira.

GDPR Article 32 is your AI Act head start.

The AI Act and GDPR call for the same engineering work: risk management (Art. 9 ↔ GDPR Art. 32), data governance (Art. 10 ↔ GDPR Art. 9), logging (Art. 12 ↔ GDPR Art. 32), human oversight (Art. 14 ↔ GDPR Art. 22), incident reporting (Arts. 72/73 ↔ GDPR Arts. 33/34). RuleMesh delivers the GDPR side today: structured IT requirements your engineers and AI agents implement through the MCP. The AI Act's requirements are coming to the same MCP.