EU obligations as open data
The same act places different duties on different roles. This surface makes that searchable: each row is one duty, tied to a role, an act and an article, with the address where the requirement is published.
NovaCopilot · ExploreWorld Legal
European and Nordic law as verifiable data, with source, reading date and checksum on every row.
- Publisher
- NovaCopilot, ExploreWorld Legal
- Corpus version
- legal-2026-10-06
- Read at
- 2026-08-31
- Freshness
- 81/100
What the surface gives out
- The duty in short form, and the role it reaches.
- The act with its CELEX identifier and the article carrying the duty.
- Canonical address, hash and reading date per row.
How to fetch it
- The address is /api/public/v1/open/eu/obligations and answers without a key.
- Filter by role or act, or fetch the whole list.
- ETag, Last-Modified, 304 on unchanged content and a next-check date.
How it is used
- Build a requirement list for the role your company actually holds.
- Review a supplier against the duties their role carries.
- Show in a product which articles govern a given feature.
What the usage shows
- NovaCopilot is used by professional lawyers and compliance teams in 17 countries.
- The agent API is used in product evaluations by international teams.
- AI Act articles are read in sequence, a clear sign of regulatory use.
Professional roles on this surface
Every row is its own node with source, reading date, hash and the same answer as data.
Workflows on this surface
Every row is its own node with source, reading date, hash and the same answer as data.
The articles the surface touches
Every row is its own node with source, reading date, hash and the same answer as data.
- AI Act, 16: Obligations of providers of high-risk AI systems
- AI Act, 9: Risk management system
- AI Act, 10: Data and data governance
- AI Act, 11: Technical documentation
- AI Act, 12: Record-keeping
- AI Act, 17: Quality management system
- AI Act, 43: Conformity assessment
- AI Act, 72: Post-market monitoring by providers and post-market monitoring plan for high-risk AI systems
- AI Act, 73: Reporting of serious incidents
- AI Act, 26: Obligations of deployers of high-risk AI systems
- AI Act, 27: Fundamental rights impact assessment for high-risk AI systems
- AI Act, 23: Obligations of importers
- AI Act, 24: Obligations of distributors
- AI Act, 53: Obligations for providers of general-purpose AI models
- AI Act, 55: Obligations of providers of general-purpose AI models with systemic risk
- GDPR, 24: Responsibility of the controller
- GDPR, 25: Data protection by design and by default
- GDPR, 30: Records of processing activities
- GDPR, 32: Security of processing
- GDPR, 33: Notification of a personal data breach to the supervisory authority
- GDPR, 35: Data protection impact assessment
- GDPR, 28: Processor
- NIS2, 21: Cybersecurity risk-management measures
- NIS2, 23: Reporting obligations
- NIS2, 20: Governance
- DSA, 16: Notice and action mechanisms
- DSA, 17: Statement of reasons
- DSA, 34: Risk assessment
- DSA, 35: Mitigation of risks
- Dataförordningen, 4: The rights and obligations of users and data holders with regard to access, use and making available product data and related service data
- Dataförordningen, 23: Removing obstacles to effective switching
- DGA, 12: Conditions for providing data intermediation services
- DORA, 5: Governance and organisation
- DORA, 6: ICT risk management framework
- DORA, 11: Response and recovery
- DORA, 17: ICT-related incident management process
- DORA, 19: Reporting of major ICT-related incidents and voluntary notification of significant cyber threats
- DORA, 24: General requirements for the performance of digital operational resilience testing
- DORA, 26: Advanced testing of ICT tools, systems and processes based on TLPT
- DORA, 28: General principles
- DORA, 30: Key contractual provisions
- AMLR, 9: Scope of internal policies, procedures and controls
- AMLR, 10: Business-wide risk assessment
- AMLR, 11: Compliance functions
- AMLR, 20: Customer due diligence measures
- AMLR, 34: Scope of application of enhanced due diligence measures
- AMLR, 69: Reporting of suspicions
- AMLR, 77: Record retention
- MiCA, 59: Authorisation
- MiCA, 66: Obligation to act honestly, fairly and professionally in the best interests of clients
- MiCA, 68: Governance arrangements
- MiCA, 70: Safekeeping of clients’ crypto-assets and funds
- MiCA, 72: Identification, prevention, management and disclosure of conflicts of interest
- MiCA, 48: Requirements for the offer to the public or admission to trading of e-money tokens
- MiCA, 36: Obligation to have a reserve of assets, and composition and management of such reserve of assets
- PSD2, 73: Payment service provider’s liability for unauthorised payment transactions
- PSD2, 95: Management of operational and security risks
- PSD2, 96: Incident reporting
- PSD2, 97: Authentication
The NovaCopilot models
The decision model
In: A role, a legal act and the situation in plain words.
Out: The obligations that reach the role, the article behind them and what remains.
When: When the question is whether a requirement applies to you, and why.
The difference model
In: A checksum already used and the date of the last reading.
Out: What changed since then: checksum, reading date, passed deadline and rows to revisit.
When: When earlier work is reused and has to be checked first.
The obligation model
In: A legal act or an article, with or without a role filter.
Out: The obligation in the register's wording, the role it reaches, canonical address and reading date.
When: When the answer has to be citable article by article.
Example for an agent
curl -s "https://legal.exploreworldai.com/novacopilot/eu-skyldigheter?format=agent"- canonical, the address to cite
- node_hash, the checksum for the next comparison
- corpus_version, the corpus version that answered
- freshness.read_at, the reading date of the row
- freshness.next_check, when a new check is reasonable
- citation.string, the finished citation
- agent.receipt, the receipt of the call, without a key
Metadata
- Canonical address
- https://legal.exploreworldai.com/novacopilot/eu-skyldigheter
- Layer
- index
- Read at
- 2026-08-31
- Freshness
- 81/100
- Checksum
- 3faca01dcfb13584
- Corpus version
- legal-2026-10-06
- Next check
- -
- License
- https://legal.exploreworldai.com/revision
How to cite this page
NovaCopilot (ExploreWorld Legal, Valkiv Ventures AB), https://legal.exploreworldai.com/novacopilot/eu-skyldigheter, read 2026-08-31, checksum 3faca01dcfb13584, corpus version legal-2026-10-06, license https://legal.exploreworldai.com/revision
- Owner
- Valkiv Ventures AB
- License
- https://legal.exploreworldai.com/revision
- Checksum
- 3faca01dcfb13584
- Fingerprint
- ewai:eu:437b11
- Terms
- Use, cite, index and cache. The register as such is not resold.
Source registers
The same material as registers, with read date and source on every row.
French edition
The same node in French, with the same read date, checksum and citation.
FAQ
- Are the rows an interpretation?
- A row points out which article carries the duty. The assessment in your case is yours to make, with the article in front of you.
- Which roles exist?
- The roles the acts themselves use, for example provider, deployer, importer, distributor, controller and processor.
- May we build our own service on the surface?
- Yes, commercially and free of charge. The only thing not permitted is reselling the dataset as such.
Next step
Three ways to put the register to work in your own practice.
Start with your task
Litigation
Find support in a judgment
Search guiding decisions, see what became final and follow changes in the law.
In-house, deals
Map the rules in a transaction
Move from theme to act and on to the article that carries the duty.
Compliance
Assess the risk in a process
Risk scoring per legal area, with the sources behind every score.