European Union
EU AI Act Articles 9 to 17 and 53
High-risk obligations: risk management (9), data governance (10), technical documentation (11), record-keeping (12), transparency (13), human oversight (14), accuracy and robustness (15), quality management (17) and general-purpose model obligations (53). Mapped one requirement at a time.
United Kingdom
UK GDPR and the Data Protection Act 2018
Data minimisation, lawful basis, data subject rights, records of processing activities, and cross-border transfer safeguards. Every data asset in the registry carries a basis and a named controller.