The Artificial Intelligence Act (AI Act) contains binding rules and obligations for key actors across the value chain of a high-risk AI system, as well as for providers of general-purpose AI (GPAI) models.
Providers of high-risk AI systems will need to comply with a series of mandatory requirements (e.g. on data and cybersecurity), conduct an ex ante conformity assessment, and develop a post-market monitoring system.
Meeting harmonised EU standards or certain common specifications will lead to a presumption of conformity with the AI Act requirements.
Public authorities and private actors providing public services will need to conduct a fundamental rights impact assessment (FRIA) if they deploy a high-risk AI system.
Providers of GPAI models will be subject to transparency requirements, e.g. publishing a detailed summary of the data used to train the model.
Cullen International is publishing a series of reports analysing different aspects of the new AI rulebook. The third report covers the core obligations for providers of AI systems and GPAI models, and for other actors in the AI value chain.
See also:
Part 1: Scope
Part 3: Governance & Enforcement
Part 4: Interplay with other EU acts
For more information and to access our AI Act report series, please click on “Access the full content” - or on “Request Access”, in case you are not subscribed to our European Digital Economy service.
more news
25 February 26
Protection of minors: overview of national initiatives on banning access to social media
Our latest benchmark shows that an increasing number of European countries are discussing a potential social media ban on children.
23 February 26
The DNA explained: universal service to serve the same goals under a revised approach
Cullen International is issuing a series of analyses on different aspects of the Digital Networks Act (DNA) proposal. This report covers universal service.
20 February 26
Revised Cybersecurity Act (CSA2) - Changes to the EU cybersecurity certification framework
Cullen International published an analysis of the proposed changes to the EU cybersecurity certification framework under the draft Cybersecurity Act 2 (CSA2) delivered by the European Commission on 20 January 2026.