The Artificial Intelligence Act (AI Act) contains binding rules and obligations for key actors across the value chain of a high-risk AI system, as well as for providers of general-purpose AI (GPAI) models.
Providers of high-risk AI systems will need to comply with a series of mandatory requirements (e.g. on data and cybersecurity), conduct an ex ante conformity assessment, and develop a post-market monitoring system.
Meeting harmonised EU standards or certain common specifications will lead to a presumption of conformity with the AI Act requirements.
Public authorities and private actors providing public services will need to conduct a fundamental rights impact assessment (FRIA) if they deploy a high-risk AI system.
Providers of GPAI models will be subject to transparency requirements, e.g. publishing a detailed summary of the data used to train the model.
Cullen International is publishing a series of reports analysing different aspects of the new AI rulebook. The third report covers the core obligations for providers of AI systems and GPAI models, and for other actors in the AI value chain.
See also:
Part 1: Scope
Part 3: Governance & Enforcement
Part 4: Interplay with other EU acts
For more information and to access our AI Act report series, please click on “Access the full content” - or on “Request Access”, in case you are not subscribed to our European Digital Economy service.
more news
26 November 25
AI policy in the Americas is at a crossroads, as many countries adopt or discuss broad strategies or legislation
Our latest benchmark, which covers artificial intelligence strategies and regulation in the Americas, shows that AI policy has been a key issue for the region, with important decisions on the horizon.
19 November 25
Latest update on telecoms regulation from the Middle East and North Africa
Our latest MENA Telecoms Update details the most significant regulatory developments taking place in the region between 12 August and 30 October 2025.
18 November 25
Cybersecurity strategies in the Americas focus on policy goals, with most not setting binding obligations
Our latest benchmark surveys main cybersecurity issues, including general policies and specific rules on critical infrastructure across the Americas.