Fingerprint & verify any document — free, no upload Try it now →

EU AI Act · Source directory

The 50 official EU AI Act sources, ranked by anchorability

The primary, load-bearing references for Regulation (EU) 2024/1689 — the law itself, the AI Office’s operative outputs, the standards and high-risk machinery, the national authorities, and the regulations it interlocks with. Each is labelled by how cleanly it can be fingerprinted and cryptographically anchored as tamper-evident evidence. Every URL was fetched and verified.

50 sources 4 tiers 19 anchor directly (A) 24 snapshot (B) 7 living surface (C) Article 50 applies in days · 2 Aug 2026
A

Anchor directly

A stable single-file artifact at a permanent URL with a fixed SHA-256 — the Official Journal PDF, guideline PDFs, DOI deposits. Fingerprint and anchor as-is.

B

Anchor a snapshot

A living HTML or consolidated page that changes over time. Anchor a dated snapshot so you can later prove which version you relied on.

C

Living surface

A dynamic database, register or dashboard (or a paywalled / not-yet-live surface). Anchor a dated export; the surface itself keeps moving.

The cleanest to anchor first

If you are building an evidence baseline before 2 August 2026, start with the Tier A documents: the Official Journal PDF of the Act (#2), the consolidated text (#4), the three core Commission Guidelines — prohibited practices/Art 5 (#8), the AI-system definition/Art 3 (#9), transparency/Art 50 (#10) — the GPAI Code of Practice (#11), and the Article 53(1)(d) training-content Template (#13). Each is a fixed artifact you can fingerprint and anchor today.

1

The Regulation and the AI Office

Regulation (EU) 2024/1689 itself, plus the operative outputs of the European Commission and the AI Office — the guidelines, the General-Purpose AI Code of Practice, and the machinery that implements the Act.

  1. EU / European Parliament + Council; published EUR-Lex / Official Journal (OJ L, 12.7.2024)

    The Act itself — the primary load-bearing legal instrument every AI-Act obligation, prohibition (Art. 5), high-risk regime (Art. 6/Annex III), GPAI (Art. 51-55) and transparency (Art. 50) traces back to.

    eur-lex.europa.eu/eli/reg/2024/1689/oj/eng
  2. EU / Publications Office of the EU (Official Journal L series)

    The as-published, page-numbered OJ PDF is the single most stable, self-contained artifact to fingerprint + anchor — it is the authoritative rendering courts and regulators cite by OJ reference.

    eur-lex.europa.eu/legal-content/EN/TXT/PDF/?uri=OJ:L_202401689
  3. EU / EUR-Lex (Publications Office)

    The canonical metadata hub for the Act: lists every consolidated version, corrigendum, and act 'based on' or 'amending' 2024/1689 — the authoritative index for detecting new delegated/implementing acts to anchor.

    eur-lex.europa.eu/legal-content/EN/ALL/?uri=CELEX:32024R1689
  4. EU / EUR-Lex consolidated legislation

    The consolidated text folds the base Regulation together with corrigenda/amendments applicable at a point in time — the version a compliance officer actually reads; each new consolidation (e.g. post-Digital-Omnibus) is a distinct dated artifact to anchor.

    eur-lex.europa.eu/eli/reg/2024/1689/2024-07-12/eng
  5. European Commission, DG CNECT. Canonical Commission explainer of Regulation (EU) 2024/1689: the four risk tiers, obligation summaries, and the staged application timeline (Feb 2025 prohibitions, Aug 2025 GPAI/governance, Aug 2026 transparency, 2027-2028 high-risk). Links out to compliance tools, guidelines, and the Service Desk. Verified HTML; note the shorter '/ai-act' slug 404s — this '/regulatory-framework-ai' slug is the live one.

    Commission's authoritative gloss on the whole Act (risk-based architecture, Arts 5/6/50/51); the page a compliance officer lands on first.

    digital-strategy.ec.europa.eu/en/policies/regulatory-framework-ai
  6. European Commission, DG CNECT — European AI Office. The central body implementing and enforcing the AI Act, esp. GPAI models; hub linking to all guidelines, codes, the AI Board/Scientific Panel/Advisory Forum, and news. This is the canonical index page from which most other operational outputs are published. Verified: standard HTML page with navigation and links.

    Art. 64 establishes the AI Office as the Commission's implementation/enforcement body for the Act (esp. GPAI, Arts 88-94); this is its official home page.

    digital-strategy.ec.europa.eu/en/policies/ai-office
  7. European Commission / AI Office (mandated single information platform). Central compliance portal offering the AI Act Explorer (browsable articles/annexes/recitals), a Compliance Checker, a Guideline Explorer, and a question-submission Service Desk cooperating with the AI Office. Multilingual. This is the machine-navigable structured surface for the Act's text and official guidance.

    Delivers the Article 62/single-information-platform mandate; the authoritative structured/browsable rendering of the Act and its guidance.

    ai-act-service-desk.ec.europa.eu/en
  8. European Commission. Guidelines interpreting the eight/nine banned practices (manipulation, social scoring, real-time remote biometric ID, etc.), published 4 Feb 2025 to accompany the Art. 5 prohibitions that applied from 2 Feb 2025. Non-binding; authoritative interpretation reserved to the CJEU. Library page links downloadable PDFs in all EU official languages plus the approving Communication.

    Directly interprets Article 5 (unacceptable-risk prohibitions) — the first enforceable obligations of the Act.

    digital-strategy.ec.europa.eu/en/library/commission-publishes-guidelines-prohibited-artificial-intelligence-ai-practices-defined-ai-act
  9. European Commission. Guidelines helping providers determine whether software qualifies as an 'AI system' under Art. 3(1), published 6 Feb 2025. Non-binding, designed to evolve. Library page links PDFs in 24 EU languages plus the approving Communication.

    Defines the scope-gating concept of the entire Act — Article 3(1) 'AI system' definition; determines whether any obligation applies at all.

    digital-strategy.ec.europa.eu/en/library/commission-publishes-guidelines-ai-system-definition-facilitate-first-ai-acts-rules-application
  10. European Commission / AI Office. Guidelines for providers and deployers on the Art. 50 transparency duties (AI-interaction disclosure, machine-readable marking of AI-generated content, deepfake and emotion-recognition/biometric-categorisation labelling), published ~20 July 2026 (page last-updated 29 July 2026) ahead of the 2 Aug 2026 application date. Policy page links the guidelines PDF, FAQs, and quick-facts.

    Directly interprets Article 50 (transparency for interactive AI, deepfakes, synthetic media) — applicable 2 Aug 2026.

    digital-strategy.ec.europa.eu/en/policies/guidelines-transparency-ai-generated-content
  11. European Commission / AI Office. The final GPAI Code of Practice delivered 10 July 2025 and endorsed by Commission + AI Board 1 Aug 2025 via adequacy decisions. Page hosts the three chapter PDFs — Transparency (with Model Documentation Form, DOCX), Copyright, and Safety & Security — as the voluntary compliance route for Chapter V obligations.

    The Article 56 Code of Practice — the presumption-of-conformity route for GPAI provider obligations (Arts 53, 55).

    digital-strategy.ec.europa.eu/en/policies/contents-code-gpai
  12. European Commission / AI Office. Guidelines (18 July 2025) clarifying who is a GPAI 'provider', how to estimate training compute, the systemic-risk threshold, and placing-on-market — operationalising Chapter V ahead of the 2 Aug 2025 GPAI rules. Library page links PDFs in all 24 EU languages plus approving Communication.

    Interprets Articles 51-56 (GPAI provider obligations, systemic-risk classification) — the operative scope test for foundation-model makers.

    digital-strategy.ec.europa.eu/en/library/guidelines-scope-obligations-providers-general-purpose-ai-models-under-ai-act
  13. European Commission / AI Office. The mandatory template (Explanatory Notice + Template, adopted 24 July 2025) that GPAI providers must use to publish a summary of data used to train their models — metadata, data-source categories, and copyright/illegal-content/data-protection governance. This FAQ page confirms use is mandatory and links to the Explanatory Notice + Template in the library (all EU languages).

    Implements Article 53(1)(d) — the training-data transparency summary obligation for GPAI providers.

    digital-strategy.ec.europa.eu/en/faqs/template-general-purpose-ai-model-providers-summarise-their-training-content
  14. European Commission / AI Office. A separate voluntary code (finalised 10 June 2026; confirmed by Commission + AI Board as an adequate voluntary compliance tool) covering Section 1 provider marking/detection of AI-generated content and Section 2 deployer labelling of deepfakes and AI-generated public-interest text. Page hosts the full-code PDF, EU labelling icons, FAQs, and drafting history.

    Voluntary compliance route for Article 50(2)/(4) marking-and-labelling of synthetic and manipulated content; applicable-date 2 Aug 2026.

    digital-strategy.ec.europa.eu/en/policies/code-practice-ai-generated-content
  15. EU / European Commission (implementing act under Art. 68 of the AI Act); OJ 10.3.2025

    First implementing act adopted under the AI Act — lays down rules for the Art. 68 scientific panel; a concrete instance of the secondary-law layer the network must track and anchor as it grows.

    eur-lex.europa.eu/eli/reg_impl/2025/454/oj/eng
  16. EU / European Commission (proposal, 19 Nov 2025) amending Reg. (EU) 2024/1689, (EU) 2018/1139 and (EU) 2023/1230

    The principal amendment to the AI Act — adjusts implementation timing and governance; must be tracked/anchored as it moves through the ordinary procedure and (per current reporting) into force, changing the applicable dates.

    eur-lex.europa.eu/legal-content/EN/TXT/?uri=celex:52025PC0836
  17. EU / European Commission AI Act Service Desk (ai-act-service-desk.ec.europa.eu)

    The official EU rendering of the phased application dates (Aug 2024 entry into force → Feb 2025 prohibitions → Aug 2025 GPAI → Aug 2026 majority → high-risk 2027/2028), reflecting Digital-Omnibus adjustments — the authoritative 'when does Article X apply' reference.

    ai-act-service-desk.ec.europa.eu/en/ai-act/timeline/timeline-implementation-eu-ai-act
  18. oeil.europarl.europa.eu/oeil/en/procedure-file?reference=2021/0106(COD
  19. EU governance body (AI Act Arts. 65-66); Commission 'Shaping Europe's digital future' portal, secretariat = AI Office.

    The Member-State coordination and advisory body the AI Act creates (effective 1 Aug 2024) to align enforcement and issue guidance/recommendations — its outputs steer harmonised application of the Act.

    digital-strategy.ec.europa.eu/en/policies/ai-board
  20. Third-party (Future of Life Institute, EU transparency register 787064543128-10) — mirrors the official text

    The most-used browsable, article-by-article rendering of Reg. (EU) 2024/1689 (with recitals/annex cross-links) that practitioners cite; useful to anchor as a fixed civil-society snapshot, but authoritative text remains EUR-Lex.

    artificialintelligenceact.eu/the-act
2

Standards, conformity and the high-risk database

The harmonised standards that create the Article 40 presumption of conformity, the bodies drafting and certifying them, and the Article 71 public database of high-risk AI systems.

  1. European Commission. The Art. 71 public register where providers/deployers log Annex-III high-risk systems (data per Annex VIII); must be operational before 2 Aug 2026 and partly publicly accessible + machine-readable (law-enforcement/migration entries restricted). No public front-end/registration portal URL is yet published — the verified authoritative reference is the Service Desk's Article 71 page (regulatory text + summary). Track for the live register going public.

    Article 71 EU database of high-risk AI systems — the central public transparency register (registration under Arts 49/60).

    ai-act-service-desk.ec.europa.eu/en/ai-act/article-71
  2. The Commission Implementing Decisions that legally task CEN-CENELEC to draft the AI Act harmonised standards. M/593 = C(2023)3215 (adopted 22 May 2023, original deliverable deadline 30 Apr 2025). M/613 = Amendment 1 = C(2025)3871 (adopted 23 June 2025) which REPEALED AND REPLACED C(2023)3215, extending the request to expiry 28 Feb 2027. Both are formally registered/published in the Commission's eNorm mandates database (searchable), where the signed PDFs live and can be fingerprinted per document.

    The Art. 40 standardisation request is the legal instrument defining the scope and content of every AI Act harmonised standard.

    ec.europa.eu/growth/tools-databases/enorm/mandate/index.cfm
  3. Official CEN-CENELEC topic page for Joint Technical Committee 21, the body drafting the European (harmonised) AI standards. Describes JTC 21 (est. 1 June 2021, 300+ experts, 5 working groups), names the Commission standardisation request M/593, and lists the flagship deliverables under development: AI Trustworthiness Framework, AI Risk Management, AI Quality Management System, AI Conformity Assessment, plus data/bias/robustness/cybersecurity/logging work items. Links out to the full work-programme database (see separate standards.cencenelec.eu entry).

    JTC 21 authors the harmonised standards that create the AI Act Art. 40 presumption of conformity for high-risk AI systems.

    www.cencenelec.eu/areas-of-work/cen-cenelec-topics/artificial-intelligence
  4. The Commission's central register of harmonised standards per piece of Union legislation, each entry linking to the Commission Implementing Decision (OJ C-series) that cites the standards and triggers presumption of conformity. This is the official surface where the AI Act's harmonised standards will receive their OJ reference once JTC 21 delivers and the Commission cites them — currently the watch-point for the first AI Act citations.

    The register/OJ pathway (Art. 40) where an AI Act harmonised standard becomes legally load-bearing via its Official Journal citation.

    single-market-economy.ec.europa.eu/single-market/goods/european-standards/harmonised-standards_en
  5. The EU's official register of notified bodies and conformity-assessment bodies, now hosted in the Single Market Compliance Space (the legacy ec.europa.eu/growth/tools-databases/nando URL redirects here). Filterable by legislation; once member states designate AI Act notified bodies under Art. 28-39 they appear here with notification scope and identification numbers. Note: the site is an Angular single-page app — the server returns only the app shell and all /api/* paths return the SPA catch-all, so there is no documented public JSON/CSV/RSS feed; data is loaded by the app's own in-browser XHR.

    Register of notified/conformity-assessment bodies (AI Act Art. 28-39) that will third-party-certify high-risk AI systems.

    webgate.ec.europa.eu/single-market-compliance-space/#/notified-bodies
  6. The ISO/IEC subcommittee that is the global focal point for AI standardisation (63 participating countries, ANSI secretariat). Produces the international standards that CEN-CENELEC adopts as EN ISO/IEC harmonised standards for the AI Act (e.g. ISO/IEC 42001 AI management system, ISO/IEC 23894 risk management, ISO/IEC 22989 concepts/terminology, ISO/IEC 42005 impact assessment).

    SC 42's international standards are the base texts CEN-CENELEC transposes into the AI Act harmonised standards (Art. 40), avoiding duplicate drafting.

    www.iso.org/committee/6794475.html
  7. Authoritative Commission (Shaping Europe's Digital Future) explainer of the AI Act standardisation chain: how a standardisation request is issued, how CEN-CENELEC JTC 21 develops harmonised standards, how they are cited in the Official Journal, and how OJ citation confers presumption of conformity. The canonical Commission status page for AI Act standardisation, updated as milestones land.

    Official Commission narrative of the Art. 40 request → hEN → OJ-citation → presumption-of-conformity mechanism.

    digital-strategy.ec.europa.eu/en/faqs/understanding-standardisation-ai-act
  8. European Commission Joint Research Centre analysis mapping the JTC 21 / ISO-IEC standardisation deliverables requested under M/593 against the AI Act's high-risk requirements, flagging coverage and gaps. The Commission's own standards-adequacy assessment — a stable primary PDF, useful both as an anchorable document and as an authoritative index of which standards map to which AI Act articles.

    JRC's authoritative mapping of harmonised-standard deliverables to AI Act Art. 8-15 high-risk requirements (the adequacy check behind Art. 40).

    publications.jrc.ec.europa.eu/repository/bitstream/JRC139430/JRC139430_01.pdf
  9. The officially recognised European accreditation infrastructure body operating the EA Multilateral Agreement (MLA). National accreditation bodies (one per member state under Reg. 765/2008) accredit the conformity-assessment bodies that member states then notify. Site exposes EA members and the MLA signatory framework.

    Accreditation is the AI Act Art. 29-31 route by which a body demonstrates competence before a member state notifies it as an AI Act notified body.

    european-accreditation.org
3

National competent authorities

The national authorities each Member State designates to supervise and enforce the Act. Many designations are still provisional — an “authority” is only load-bearing once national law is in force, so treat this tier as a living surface.

Designation status (verify before relying on any single authority): firmly designated by binding law — Italy, Spain, Denmark, Lithuania, Ireland, Malta, Czechia, Slovenia, Luxembourg, Cyprus. Named but provisional — France (CNIL, draft), Germany (BNetzA), Belgium (BIPT), Netherlands. Draft / pending — Poland, Slovakia, Romania, Croatia, Sweden. Not yet designated — Bulgaria, Greece, Latvia. EEA-EFTA pending incorporation — Norway (Nkom).
  1. Official portal of Spain's dedicated AI supervisory agency (attached to the Ministry for Digital Transformation, HQ A Coruña), the first standalone national AI agency in the EU, operational since 2024. Site publishes the agency's guides, news/'Present' newsroom, and a citizen complaints mailbox for AI-rule infringements. Verified live; EN and ES versions.

    Spain's Art. 70 national competent authority / market-surveillance authority + single point of contact under Regulation (EU) 2024/1689; flagship first-mover AI regulator.

    aesia.digital.gob.es/en
  2. Under Law No. 132/2025 (first national AI law in the EU), ACN is the market-surveillance authority and single point of contact with EU institutions (and chairs the ADCO AI cooperation group), while AgID is the notifying authority for notified bodies; Bank of Italy, CONSOB and IVASS keep sectoral MSA roles. Official ACN portal, which carries the AI-Act market-surveillance news stream.

    Italy's designated Art. 70 market-surveillance authority and single point of contact under Law 132/2025 (AgID = notifying authority, Art. 28).

    www.acn.gov.it
  3. Under the Sept 2025 DGE draft designation, ~17 authorities are named French market-surveillance authorities, with CNIL (data-protection regulator) the lead body covering the most AI use-cases and DGCCRF the coordinating single point of contact; parliamentary adoption expected through 2026. CNIL's AI hub carries its AI-Act Q&A, recommendations and enforcement news.

    France's lead Art. 70 market-surveillance authority for the AI Act (designation being finalised; DGCCRF is coordinating SPOC).

    www.cnil.fr/en/artificial-intelligence-ai
  4. BNetzA is designated Germany's default market-surveillance authority and single point of contact for the EU AI Office (DAkkS is notifying authority; BaFin covers financial high-risk AI); formalised by the KI-MIG bill (Cabinet-adopted Feb 2026). Official English page on BNetzA's market-surveillance role for radio-equipment (Annex I) and Annex III systems.

    Germany's designated Art. 70 default market-surveillance authority and single point of contact for the AI Act.

    www.bundesnetzagentur.de/EN/Areas/Digitalisation/AI/14_MarketSurveillance/start.html
  5. The Department of Enterprise, Tourism and Employment (DETE) hosts Ireland's National AI Office and national single point of contact; 15 national competent authorities were designated across 2025 (SI No. 366/2025 formalised on 29 Jul 2025; further authorities added 16 Sep 2025), including the Central Bank, DPC and Coimisiún na Meán. Official DETE AI landing page.

    Ireland's Art. 70 single point of contact and hub for its 15 designated national competent authorities under the AI Act.

    enterprise.gov.ie/en/what-we-do/innovation-research-development/artificial-intelligence
  6. Dutch DPA's official EU AI Act hub (English). The AP and the Rijksinspectie Digitale Infrastructuur (RDI) jointly coordinate Dutch AI supervision under a decentralised, ~10-authority sector model; RDI is the Art. 70(2) single point of contact, AP is MSA for prohibited practices and most Annex III high-risk systems. Draft Uitvoeringswet AI-verordening in consultation 2026.

    Netherlands' coordinating Art. 70 competent authority stream (AP + RDI); AP is MSA for Art. 5 prohibited practices and Annex III high-risk systems.

    www.autoriteitpersoonsgegevens.nl/en/themes/algorithms-ai/eu-ai-act
  7. Digitaliseringsstyrelsen is Denmark's notifying authority, coordinating/primary market-surveillance authority and single point of contact (designated in 2024, confirmed by the 2025 supplementary AI-Act implementation law — one of the EU's first). Datatilsynet and the Court Administration complete the MSA framework. This is the agency's AI-Act (AI-forordningen) supervision hub; it publishes Article 5 prohibited-practice guidance.

    Denmark's Art. 70 notifying authority + primary market-surveillance authority + SPOC; publishes Art. 5 prohibited-practices guidance.

    digst.dk/tilsyn/ai-forordningen
  8. Malta's official-gazette legal instrument (Gov. Gazette No. 21,519, 10.10.2025) on the national legislation portal, ELI-addressed English text. Designates the Malta Digital Innovation Authority (MDIA) as default national market-surveillance authority, single point of contact, notifying authority and AI-sandbox operator; LN 227/2025 adds the IDPC for data-sensitive/law-enforcement AI. (MDIA's own page mdia.gov.mt/services/artificial-intelligence returns HTTP 403 to automated fetch — Cloudflare bot-block — so the gazette ELI is the clean anchor.)

    Malta's binding Art. 70 designation of MDIA as MSA/SPOC + Art. 28 notifying authority; immutable official-gazette instrument.

    legislation.mt/eli/ln/2025/226/eng
  9. Communications Regulatory Authority (RRT) dedicated 'DI reguliavimas' (AI regulation) page within its digital-space section. From 1 April 2025 RRT is Lithuania's national market-surveillance authority and single point of contact; Innovation Agency Lithuania is the notifying authority and sandbox operator. One of the first EU states to complete designation. Lithuanian-language.

    Lithuania's Art. 70 MSA + single point of contact; RRT runs inspections/enforcement of high-risk AI under the Act.

    rrt.lt/veiklos-sritys/skaitmenine-erdve/di-informacija/di-reguliavimas
  10. Traficom is Finland's national coordinator and single point of contact for the European Commission / AI Office, runs the national AI regulatory sandbox and coordinates a decentralised model of sectoral market-surveillance authorities (powers took effect Jan 2026). Official English AI-regulation hub.

    Finland's Art. 70 coordinating authority and single point of contact for the AI Act.

    traficom.fi/en/ai-regulation
  11. The Czech Telecommunication Office (ČTÚ) is designated primary market-surveillance authority and single point of contact under the Czech AI adaptation act (in force during 2026); shares supervision with the Czech National Bank and the Office for Personal Data Protection. Official ČTÚ AI landing page (ctu.gov.cz).

    Czechia's designated Art. 70 primary market-surveillance authority and SPOC for the AI Act.

    ctu.gov.cz/umela-inteligence
  12. Belgian Institute for Postal Services and Telecommunications (BIPT), designated main AI-Act regulator / market-surveillance authority per the Jan 2025 government declaration and 2025–2029 federal agreement (FPS Economy coordinates overall implementation). This is BIPT's dedicated AI-Act operator section.

    Belgium's designated Art. 70 market-surveillance authority for the AI Act (full institutional designation still being finalised).

    www.bipt.be/operators/digital/ia-act/application-of-the-ai-act
  13. Luxembourg DPA's official news item (English) on the November 2024 bill designating the CNPD as AI Act single point of contact, national coordinator, default market-surveillance authority (Annex III + residual systems), fundamental-rights authority (with ALIA and ITM) and sandbox operator; sectoral MSAs (CSSF, CAA, JSA, ILR, ILNAS) sit alongside. Part of CNPD's dated 'actualités' stream.

    Luxembourg's Art. 70 SPOC + default MSA and Art. 77 fundamental-rights authority under the AI Act.

    cnpd.public.lu/en/actualites/national/2024/11/cnpd-ai-act.html
  14. Slovenian Agency for Communication Networks and Services (AKOS) official AI area (English 'Supervision of AI systems' FAQ; SL hub at /umetna-inteligenca). Under Slovenia's adopted implementing act AKOS is the central authority: national single point of contact, a market-surveillance authority, sandbox competent authority and SME entry point; other MSAs include the Information Commissioner, Bank of Slovenia and Market Inspectorate.

    Slovenia's Art. 70 central competent authority + SPOC and Art. 57/58 sandbox authority under the AI Act.

    www.akos-rs.si/en/umetna-inteligenca/explore/frequently-asked-questions-and-answers/supervision-of-ai-systems
  15. Portuguese communications regulator ANACOM's official AI-Act content (anacom.pt). By Government decision of 19 Sept 2025 ANACOM is Portugal's national market-surveillance authority and single point of contact, coordinating with Banco de Portugal, CMVM, ASF and CNPD. ANACOM also runs public consultations on Art. 5 (prohibited practices) and Art. 50 (transparency) guidance and maintains the Art. 77 fundamental-rights-authorities list — an evolving official stream.

    Portugal's Art. 70 MSA + single point of contact; ANACOM issues Art. 5 and Art. 50 implementation guidance.

    www.anacom.pt/render.jsp?contentId=1802398
4

Adjacent EU regulation and case law

The regulations the AI Act interlocks with — data protection, platform, financial-resilience and cyber-resilience law — and the case law that will shape its interpretation.

  1. EU / European Parliament & Council; Official Journal via EUR-Lex (Publications Office). ELI permalink is the canonical stable citation.

    Baseline personal-data regime the AI Act sits on top of: AI Act Art. 10(5) special-category data for bias detection, Recital 10 GDPR-unaffected clause, and DPIA linkage in Art. 26 — every high-risk/GPAI data-governance duty cross-refers to it.

    eur-lex.europa.eu/eli/reg/2016/679/oj
  2. EU / European Parliament & Council; EUR-Lex. Twin medical-device instruments (MDR 2017/745, IVDR 2017/746).

    AI Act Annex I (Section A) harmonisation law: medical-device / IVD software that is or embeds AI is high-risk, with conformity assessed by MDR/IVDR notified bodies — the single largest high-risk AI channel.

    eur-lex.europa.eu/eli/reg/2017/745/oj
  3. EU / European Parliament & Council; EUR-Lex.

    Explicitly listed in AI Act Annex I (Section A) Union harmonisation law: an AI system that is a safety component of machinery is high-risk and its conformity runs through this Regulation — a direct load-bearing cross-reference.

    eur-lex.europa.eu/eli/reg/2023/1230/oj
  4. European Data Protection Board (edpb.europa.eu); Opinion of the Board under GDPR Art. 64, requested by the Irish DPA.

    Authoritative EU-level guidance on the AI Act × GDPR seam — when an AI model is 'anonymous', and legitimate-interest legal bases for training/deployment; the reference doc regulators cite on AI-model data protection.

    www.edpb.europa.eu/our-work-tools/our-documents/opinion-board-art-64/opinion-282024-certain-data-protection-aspects_en
  5. Court of Justice of the European Union (curia.europa.eu); binding interpretation of the AI Act and interlocking regs.

    Where the AI Act and its neighbours are authoritatively interpreted (e.g. automated-decision caselaw under GDPR Art. 22, SCHUFA C-634/21); CJEU judgments settle contested AI-Act meaning.

    curia.europa.eu/juris/recherche.jsf?language=en
  6. EU / European Parliament & Council; EUR-Lex.

    Interlocks with AI Act Art. 15 (accuracy, robustness, cybersecurity): high-risk AI products with digital elements meeting CRA requirements gain a presumption of conformity on cybersecurity — the two conformity regimes are designed to dovetail.

    eur-lex.europa.eu/eli/reg/2024/2847/oj

Frequently asked

Where can I read the full text of the EU AI Act?

The authoritative text is Regulation (EU) 2024/1689, published in the Official Journal of the EU. Read the as-published OJ L-series PDF or the EUR-Lex consolidated version — both are linked in the list above.

What is Regulation (EU) 2024/1689?

It is the formal legal identifier (CELEX 32024R1689) of the EU AI Act, the first comprehensive AI law. It entered into force on 1 August 2024 and applies in phases, with the Article 50 transparency obligations applying from 2 August 2026.

Is the Official Journal PDF the authoritative version?

Yes. The OJ L-series PDF is the as-published, page-numbered rendering that courts and regulators cite by Official Journal reference. Because it is a stable single-file artifact, it is also the cleanest source to fingerprint and cryptographically anchor.

What is the General-Purpose AI Code of Practice?

It is the Article 56 voluntary route by which providers of general-purpose AI models can demonstrate the presumption of conformity for their Chapter V obligations. Its final three chapters — Transparency, Copyright, and Safety & Security — were published in 2025.

Can I use these sources as audit evidence?

You can anchor a dated snapshot of any of them to create tamper-evident, independently verifiable evidence that a given version existed at a given time. That produces evidence — whether it satisfies a particular obligation is a determination your auditor, regulator, or counsel makes, not the tool.

See these sources anchored — live

LedgerProof continuously fingerprints official public-record sources — the EU Official Journal, EUR-Lex, TED, CJEU and more — and cryptographically anchors them, so anyone can independently verify that a given version of a document existed, unaltered, at a given time.

Open the live record network →

Related reading

LedgerProof produces independently verifiable evidence, not a verdict — it does not make any source, or you, “compliant.” Whether anchored evidence satisfies a given obligation is a determination your auditor, regulator, or counsel makes. Authoritative text always remains the version on EUR-Lex / the Official Journal; third-party mirrors are for convenience only. Proofs are tamper-evident, not tamper-proof.