What the AI Act is, and why it exists
The EU Artificial Intelligence Act (Regulation (EU) 2024/1689) is the first comprehensive, horizontal law governing artificial intelligence. It was published in the Official Journal on 12 July 2024 and entered into force on 1 August 2024. As a Regulation, it is directly applicable in all 27 Member States without national transposition.
Its goals are to ensure AI placed on the EU market is safe and respects fundamental rights, to give businesses legal certainty, to strengthen governance and enforcement, and to prevent a fragmented single market. The core design idea is a risk-based, product-safety approach: the Act regulates uses of AI by the risk they pose — from outright bans, through a heavy conformity regime for "high-risk" uses, down to light transparency duties and, for most systems, nothing mandatory at all.
What is covered — and who
An "AI system" (Art. 3(1)) is a machine-based system that operates with some autonomy, may adapt after deployment, and infers from its inputs how to generate outputs — predictions, content, recommendations, or decisions — that influence physical or virtual environments. Simple deterministic, rules-based software generally falls outside this definition.
The Act assigns duties by role: providers (who build/brand and place AI on the market), deployers (who use it professionally), importers, and distributors. Most organisations are deployers. A crucial twist under Article 25/26: a deployer can become a provider if it puts its own name on a high-risk system, substantially modifies one, or repurposes a system so it becomes high-risk.
Exclusions. The Act does not apply to AI used exclusively for military/defence/national-security purposes, to systems developed and used solely for scientific R&D, to pure pre-market research and testing, or to purely personal non-professional use. Free and open-source AI is largely exempt unless it is a prohibited practice, a high-risk system, or a GPAI model.
The four risk tiers
The Act sorts AI uses into four bands. Most systems fall in the bottom tier and carry no mandatory obligation.
Prohibited (Art. 5)
Banned outright since 2 Feb 2025.
Full obligations (Art. 8–27)
Annex I safety components + Annex III use cases.
Transparency (Art. 50)
Disclosure duties, not the full regime.
No mandatory duty
The vast majority of systems.
General-purpose AI (GPAI) & systemic-risk models
GPAI models are a separate, cross-cutting category (Title V) layered on top of the four tiers. A general-purpose AI model shows significant generality and can perform a wide range of distinct tasks — the foundation/large language models behind today's chatbots and coding assistants. There are two levels of obligation:
- All GPAI models — Article 53: maintain technical documentation, inform downstream integrators, adopt an EU copyright/TDM-opt-out policy, and publish a summary of training content. Open-source GPAI is exempt from some documentation duties unless it has systemic risk.
- GPAI with systemic risk — Article 55: additional duties triggered when training compute exceeds 1025 FLOP (presumption) or by Commission designation — model evaluation, adversarial testing (red-teaming), systemic-risk mitigation, serious-incident reporting to the AI Office, and model-level cybersecurity.
A voluntary GPAI Code of Practice, facilitated by the AI Office and published in 2025, offers a presumption-of-conformity route while harmonised standards are developed. GPAI obligations have applied since 2 August 2025.
The key articles, explained
Each article below carries an anchor id so Shadow AI Discovery reports can deep-link straight to the obligation behind a finding.
Prohibited AI practices
All actorsBans AI uses judged to pose unacceptable risk, applicable since 2 Feb 2025. The list covers subliminal/manipulative techniques that cause harm; exploitation of vulnerabilities (age, disability, social/economic situation); social scoring; individual crime-risk prediction from profiling alone; untargeted scraping of facial images; emotion recognition in the workplace and schools; biometric categorisation inferring sensitive attributes; and — with narrow, authorised law-enforcement exceptions — real-time remote biometric identification in public spaces.
Risk-management system
Provider · high-riskRequires a continuous, iterative risk-management system across the entire lifecycle of a high-risk system: identify known and foreseeable risks; estimate risk under intended use and reasonably foreseeable misuse; evaluate post-market data; and adopt targeted risk-control measures. Residual risks must be judged acceptable, and the system must be tested against defined metrics before deployment and throughout development, with special attention to children and vulnerable groups.
Data and data governance
Provider · high-riskTraining, validation, and testing datasets must meet quality criteria and be governed for origin, preparation, assumptions, suitability, and examination for biases affecting health, safety, or rights. Datasets should be relevant, sufficiently representative, and as far as possible free of errors and complete for the intended purpose. Limited processing of special-category data is permitted strictly for bias detection and correction, with safeguards.
Record-keeping (logging)
Provider · DeployerHigh-risk systems must automatically log events over their lifetime, to a degree appropriate to their purpose, to ensure traceability, support post-market monitoring (Art. 72), and flag situations that may present a risk or a substantial modification. Deployers must keep the logs (generally at least six months). Minimum log content is specified for certain biometric systems.
Transparency & instructions to deployers
Provider · high-riskHigh-risk systems must be sufficiently transparent for deployers to interpret and use output appropriately, and must ship with instructions for use covering the provider's identity, intended purpose, performance and known limitations, human-oversight measures, expected lifetime, and maintenance. (Distinct from Art. 50, which is transparency to end users.)
Human oversight
Provider · DeployerHigh-risk systems must be designed so humans can effectively oversee them in use — understanding capabilities and limits, staying alert to automation bias, correctly interpreting output, deciding not to use or to override, and being able to intervene or stop the system. For certain biometric identification, a "four-eyes" principle (verification by two competent people) applies.
Transparency to users & synthetic content
Provider · DeployerApplies from 2 Aug 2026: chatbots must tell people they are dealing with an AI; generative-AI output must be marked in a machine-readable format as artificially generated; deployers must disclose deepfakes and AI-generated public-interest text; and people exposed to emotion-recognition or biometric-categorisation systems must be informed.
GPAI provider obligations
GPAI providerBaseline duties for all general-purpose AI model providers: maintain up-to-date technical documentation (training/testing and evaluation); provide documentation to downstream providers; adopt a policy to comply with EU copyright law including honouring TDM opt-outs; and publish a sufficiently detailed summary of training content per the AI Office template. Open-source GPAI gets relief from some documentation duties (not the copyright and training-summary duties).
GPAI systemic-risk obligations
GPAI · systemicAdditional duties for GPAI models with systemic risk (≥1025 FLOP or Commission designation): perform model evaluation with standardised protocols and adversarial testing (red-teaming); assess and mitigate systemic risks and their sources; track, document, and report serious incidents to the AI Office without undue delay; and ensure an adequate level of cybersecurity for the model and its physical infrastructure.
Post-market monitoring
Provider · high-riskProviders must establish a post-market monitoring system proportionate to the system's risks, actively and systematically collecting, documenting, and analysing performance data over the lifetime — feeding back into the Art. 9 risk process. Serious incidents are separately reportable under Art. 73.
Deployer obligations (& becoming a provider)
DeployerArt. 26 sets deployer duties for high-risk systems: use the system per the provider's instructions, assign competent human oversight, ensure input data is relevant, keep logs, inform affected workers and persons, and cooperate with authorities. Art. 25 is the trap: put your name on a high-risk system, substantially modify it, or change its intended purpose so it becomes high-risk, and you inherit the full provider obligation set.
Annex III & Annex IV
Annex III — high-risk use cases
Lists the domains that make a stand-alone AI system high-risk (subject to the Art. 6(3) "no significant risk" filter):
- Biometrics — remote identification, sensitive-attribute categorisation, emotion recognition.
- Critical infrastructure — safety components for traffic, water, gas, heating, electricity, digital infrastructure.
- Education & vocational training — admissions, learning-outcome evaluation, exam monitoring.
- Employment — recruitment/selection (CV screening, ranking), promotion, termination, task allocation, performance monitoring.
- Essential private & public services — benefits eligibility, creditworthiness/credit scoring, life & health insurance risk & pricing, emergency triage.
- Law enforcement — risk assessment, polygraph-type tools, evidence-reliability evaluation, profiling.
- Migration, asylum & border control — risk assessment, application examination.
- Administration of justice & democratic processes — assisting judicial authorities; influencing elections/voting.
Annex IV — technical documentation
Specifies the contents of the technical-documentation file a high-risk provider must compile and keep current: a general description and intended purpose; design specifications, architecture, and development process; data requirements and datasets; human-oversight measures; validation/testing procedures and metrics (accuracy, robustness, cybersecurity, bias results); the risk-management system; lifecycle changes; and the EU declaration of conformity. This is the evidence file behind the CE marking.
Obligations by role
If you build or brand the AI, you're a provider and carry most obligations. If you use AI from someone else, you're a deployer. Watch Art. 25 for role flips.
| Obligation area | Provider (high-risk) | Deployer (high-risk) | Importer / Distributor |
|---|---|---|---|
| Risk management (Art. 9) | Build & maintain | Feed monitoring back | — |
| Data governance (Art. 10) | Yes | Relevant input data | — |
| Technical docs (Annex IV) | Compile | Keep instructions/logs | Verify present |
| Logging (Art. 12) | Design in | Keep logs ≥6mo | — |
| Instructions & oversight (Art. 13/14) | Provide/design | Follow & staff | Check accompanied |
| Conformity + CE (Art. 43/47/48) | Yes | — | Verify marks |
| Deployer duties (Art. 26) | — | Yes | — |
| Fundamental-rights impact (Art. 27) | — | Certain deployers | — |
| AI literacy (Art. 4) | Yes | Yes | Yes |
| GPAI duties (Art. 53/55) | GPAI providers | Rely on upstream docs | — |
The compliance timeline
Penalties
Fines are capped at the higher of a fixed amount or a percentage of total worldwide annual turnover (for SMEs/start-ups, the lower). National authorities enforce most breaches; the Commission's AI Office enforces GPAI directly.
| Breach | Maximum fine |
|---|---|
| Prohibited practices (Art. 5) | €35M or 7% of global annual turnover |
| Most other obligations (high-risk, transparency, provider/deployer duties) | €15M or 3% of global annual turnover |
| Incorrect/misleading information to authorities | €7.5M or 1% of global annual turnover |
| GPAI providers (Commission-enforced) | €15M or 3% of global annual turnover |
How to comply — a working checklist
- Inventory & classify. Build a live inventory of every AI system — sanctioned and shadow — and record your role and each system's intended purpose. Screen against Art. 5, Annex I/III, Art. 50, and the GPAI definition.
- Cover what's already in force. Confirm no prohibited practices; stand up an AI-literacy programme (Art. 4).
- For each high-risk system (by 2 Aug 2026). Establish the Art. 9 risk-management system, evidence Art. 10 data governance, compile Annex IV docs, enable Art. 12 logging, provide Art. 13 instructions and Art. 14 oversight, meet Art. 15 accuracy/robustness/cybersecurity, run the Art. 43 conformity assessment, draw up the Art. 47 declaration, affix CE marking, and register (Art. 71).
- For limited-risk (by 2 Aug 2026). Add AI-disclosure to chatbots; mark synthetic content and label deepfakes (Art. 50).
- If you provide/self-host GPAI (now in force). Maintain Art. 53 documentation, copyright/TDM policy, and a training-content summary; add Art. 55 controls if systemic-risk.
- Govern continuously. Monitor for re-tiering, retain evidence, rehearse incident reporting, and map controls to NIST AI RMF, ISO/IEC 42001, and the OWASP LLM Top 10 to reuse evidence.
Glossary
- AI system
- Machine-based system with autonomy that infers outputs from inputs (Art. 3(1)).
- AI Office
- The Commission body overseeing GPAI and coordinating implementation.
- Annex III
- List of high-risk use-case domains for stand-alone AI systems.
- Annex IV
- Required contents of the technical-documentation file.
- CE marking
- Conformity marking affixed after a successful conformity assessment (Art. 48).
- Conformity assessment
- Process proving a high-risk system meets the requirements (Art. 43).
- Deployer
- Entity using an AI system under its authority, professionally.
- Deepfake
- AI-generated/manipulated media that would falsely appear authentic.
- GPAI model
- General-purpose (foundation) model usable across many downstream tasks.
- FLOP
- Floating-point operations; ≥1025 FLOP presumes systemic risk.
- FRIA
- Fundamental-rights impact assessment for certain deployers (Art. 27).
- Provider
- Entity that develops and places an AI system/GPAI model on the market under its own name.
- Serious incident
- Incident leading to death, serious harm, critical-infrastructure disruption, or rights breach (Art. 73).
- Systemic risk
- Risk from high-impact GPAI capabilities with significant EU-market effect (Art. 51).
- TDM opt-out
- Text-and-data-mining rights reservation that GPAI training must respect.
Official references
- Regulation (EU) 2024/1689 — full text (EUR-Lex)The authoritative consolidated text of the AI Act.
- EUR-Lex Official Journal record (all languages/formats)OJ L, 2024/1689, 12 July 2024.
- European Commission — AI Act policy hubOverview, FAQs, and the implementation timeline.
- European Commission — European AI OfficeThe body overseeing GPAI and coordinating enforcement.
- GPAI Code of PracticeVoluntary route to demonstrate GPAI compliance.
- EU AI Act Explorer (unofficial)Article-by-article navigation and recitals.