Citations
Official references
Every finding, metric and estimate on this platform links back to a primary source. We only cite official texts and publishers: legislation from EUR-Lex, guidance from the European Commission and the EDPB, standards from OWASP, NIST and MITRE, and the maintainers' own documentation for the tools we recommend. Links were last checked on 2026-09-29.
- 97 primary sources
- Links checked 2026-09-29
EU AI Act application dates
Source: Timeline for the implementation of the EU AI Act (reflects Digital Omnibus on AI amendments), European Commission, AI Act Service Desk. These dates reflect the Digital Omnibus on AI and supersede the original dates in Article 113.
2 February 2025
In force
Prohibited practices (Article 5) and general provisions apply
2 August 2025
In force
Rules for general-purpose AI models and governance apply
2 August 2026
In force
Most rules apply, including transparency obligations (Article 50)
2 December 2027
Upcoming
High-risk rules for Annex III systems apply (amended by the Digital Omnibus on AI)
2 August 2028
Upcoming
High-risk rules for AI in products covered by Annex I apply (amended by the Digital Omnibus on AI)
Showing 97 of 97 sources
Legislation (13)
- Regulation (EU) 2024/1689 (Artificial Intelligence Act), Official Journal EUR-Lex, Publications Office of the European Union
- AI Act, Article 5: Prohibited AI practices EUR-Lex
- AI Act, Article 6: Classification rules for high-risk AI systems EUR-Lex
- AI Act, Article 9: Risk management system EUR-Lex
- AI Act, Article 12: Record-keeping EUR-Lex
- AI Act, Article 14: Human oversight EUR-Lex
- AI Act, Article 15: Accuracy, robustness and cybersecurity EUR-Lex
- AI Act, Article 26: Obligations of deployers of high-risk AI systems EUR-Lex
- AI Act, Article 50: Transparency obligations EUR-Lex
- AI Act, Annex I: Union harmonisation legislation (incl. MDR 2017/745, IVDR 2017/746) EUR-Lex
- AI Act, Annex III: High-risk AI systems referred to in Article 6(2) EUR-Lex
- Regulation (EU) 2016/679 (General Data Protection Regulation) EUR-Lex
- Directive 2002/58/EC (ePrivacy Directive), Article 5(3) EUR-Lex
Regulator guidance (5)
- Timeline for the implementation of the EU AI Act (reflects Digital Omnibus on AI amendments) European Commission, AI Act Service Desk
- AI Act Service Desk: Article 50 European Commission, AI Act Service Desk
- AI Act Service Desk: Annex III European Commission, AI Act Service Desk
- Guidelines 05/2020 on consent under Regulation 2016/679 European Data Protection Board
- Guidelines 2/2023 on the technical scope of Art. 5(3) of the ePrivacy Directive European Data Protection Board
Standards and frameworks (38)
- OWASP Top 10 for LLM Applications 2025 OWASP GenAI Security Project
- LLM01:2025 Prompt Injection OWASP GenAI Security Project
- LLM02:2025 Sensitive Information Disclosure OWASP GenAI Security Project
- LLM03:2025 Supply Chain OWASP GenAI Security Project
- LLM04:2025 Data and Model Poisoning OWASP GenAI Security Project
- LLM05:2025 Improper Output Handling OWASP GenAI Security Project
- LLM06:2025 Excessive Agency OWASP GenAI Security Project
- LLM07:2025 System Prompt Leakage OWASP GenAI Security Project
- LLM08:2025 Vector and Embedding Weaknesses OWASP GenAI Security Project
- LLM09:2025 Misinformation OWASP GenAI Security Project
- LLM10:2025 Unbounded Consumption OWASP GenAI Security Project
- LLM Prompt Injection Prevention Cheat Sheet OWASP Cheat Sheet Series
- SQL Injection Prevention Cheat Sheet OWASP Cheat Sheet Series
- Cross Site Scripting Prevention Cheat Sheet OWASP Cheat Sheet Series
- Content Security Policy Cheat Sheet OWASP Cheat Sheet Series
- Logging Cheat Sheet OWASP Cheat Sheet Series
- MITRE ATLAS (Adversarial Threat Landscape for AI Systems) MITRE
- Artificial Intelligence Risk Management Framework (AI RMF 1.0), NIST AI 100-1 NIST
- AI RMF 1.0, GOVERN 6.1 (Table 1) NIST
- AI RMF 1.0, GOVERN 3.2 (Table 1) NIST
- AI RMF 1.0, MAP 1.1 (Table 2) NIST
- AI RMF 1.0, MEASURE 2.4 (Table 3) NIST
- AI RMF 1.0, MEASURE 2.7 and 2.10 (Table 3) NIST
- AI RMF 1.0, MEASURE 3.1 (Table 3) NIST
- AI RMF 1.0, MANAGE 2.4 and 3.2 (Table 4) NIST
- AI RMF 1.0, MANAGE 4.1 (Table 4) NIST
- Generative AI Profile, NIST AI 600-1 NIST
- NIST AI 600-1, §2.2 Confabulation NIST
- NIST AI 600-1, §2.4 Data Privacy NIST
- NIST AI 600-1, §2.9 Information Security NIST
- NIST AI 600-1, §2.12 Value Chain and Component Integration NIST
- NIST AI RMF Playbook NIST Trustworthy and Responsible AI Resource Center
- OpenTelemetry semantic conventions for generative AI OpenTelemetry (CNCF)
- OpenID Connect Core 1.0 OpenID Foundation
- FinOps for AI overview FinOps Foundation
- FOCUS: FinOps Open Cost and Usage Specification FinOps Foundation
- ISO/IEC 42001:2023 Artificial intelligence: Management system ISO/IEC (IEC Webstore)
- ISO/IEC 23894:2023 Artificial intelligence: Guidance on risk management ISO/IEC (IEC Webstore)
Official statistics (1)
Official tool and provider documentation (40)
- NeMo Guardrails: self-check input and output rails NVIDIA
- Presidio Anonymizer Microsoft
- Pydantic: JSON validation Pydantic
- Safetensors documentation Hugging Face
- Transformers: from_pretrained (revision, use_safetensors, trust_remote_code) Hugging Face
- rehype-sanitize unified collective (rehypejs)
- Content Security Policy (CSP) MDN Web Docs (Mozilla)
- Upstash Ratelimit (TypeScript SDK) Upstash
- Amazon Bedrock: interface VPC endpoints (AWS PrivateLink) Amazon Web Services
- Configure virtual networks for Azure AI services Microsoft Learn
- Amazon S3 Object Lock Amazon Web Services
- DeepEval: Faithfulness metric Confident AI (DeepEval)
- DeepEval: Contextual Precision metric Confident AI (DeepEval)
- DeepEval: Contextual Recall metric Confident AI (DeepEval)
- DeepEval: Answer Relevancy metric Confident AI (DeepEval)
- Ragas: Context Precision Ragas
- Ragas: Faithfulness Ragas
- LiteLLM model_prices_and_context_window.json BerriAI (LiteLLM)
- OpenAI API pricing OpenAI
- OpenAI: Prompt caching OpenAI
- Claude pricing Anthropic
- Claude: Prompt caching Anthropic
- Amazon Bedrock pricing Amazon Web Services
- Amazon Bedrock: Prompt caching Amazon Web Services
- GraphRAG Microsoft Research
- Hybrid search overview: Azure AI Search Microsoft Learn
- pgvector: open-source vector similarity search for Postgres pgvector project
- LiteLLM AI Gateway (LLM Proxy) BerriAI (LiteLLM)
- AI gateway capabilities in Azure API Management Microsoft Learn
- Amazon Bedrock Knowledge Bases Amazon Web Services
- RAG Engine overview (Gemini Enterprise Agent Platform) Google Cloud
- Vector Search (Gemini Enterprise Agent Platform) Google Cloud
- What is Microsoft Entra? Microsoft Learn
- What is IAM Identity Center? Amazon Web Services
- Overview of Cloud Identity Google Cloud
- Amazon Bedrock: customize your model Amazon Web Services
- Amazon Bedrock Guardrails Amazon Web Services
- What is Azure AI Content Safety? Microsoft Learn
- Deployment types in Microsoft Foundry Models (data zones) Microsoft Learn
- Amazon Bedrock inference profiles (cross-Region inference) Amazon Web Services