Home / Knowledge Base / EU AI Act
Regulation (EU) 2024/1689

The EU AI Act, explained for security teams.

The world's first comprehensive AI law takes a risk-based, product-safety approach: the higher the risk an AI use poses to health, safety, and fundamental rights, the stricter the obligations. This is a plain-English walkthrough of the risk tiers, the key articles, GPAI duties, the compliance timeline, and the penalties — the same sources our reports map your findings against.

In force: 1 Aug 2024 Bans apply: 2 Feb 2025 GPAI: 2 Aug 2025 High-risk: 2 Aug 2026 Max fine: €35M / 7%
Overview

What the AI Act is, and why it exists

The EU Artificial Intelligence Act (Regulation (EU) 2024/1689) is the first comprehensive, horizontal law governing artificial intelligence. It was published in the Official Journal on 12 July 2024 and entered into force on 1 August 2024. As a Regulation, it is directly applicable in all 27 Member States without national transposition.

Its goals are to ensure AI placed on the EU market is safe and respects fundamental rights, to give businesses legal certainty, to strengthen governance and enforcement, and to prevent a fragmented single market. The core design idea is a risk-based, product-safety approach: the Act regulates uses of AI by the risk they pose — from outright bans, through a heavy conformity regime for "high-risk" uses, down to light transparency duties and, for most systems, nothing mandatory at all.

The "Brussels effect." Like the GDPR, the Act reaches beyond the EU. It applies to providers and deployers outside the EU wherever an AI system's output is used in the EU, so most global vendors align to it. It sits alongside — and does not replace — the GDPR, sector safety law, and cybersecurity law such as NIS2 and the Cyber Resilience Act.

Scope

What is covered — and who

An "AI system" (Art. 3(1)) is a machine-based system that operates with some autonomy, may adapt after deployment, and infers from its inputs how to generate outputs — predictions, content, recommendations, or decisions — that influence physical or virtual environments. Simple deterministic, rules-based software generally falls outside this definition.

The Act assigns duties by role: providers (who build/brand and place AI on the market), deployers (who use it professionally), importers, and distributors. Most organisations are deployers. A crucial twist under Article 25/26: a deployer can become a provider if it puts its own name on a high-risk system, substantially modifies one, or repurposes a system so it becomes high-risk.

Exclusions. The Act does not apply to AI used exclusively for military/defence/national-security purposes, to systems developed and used solely for scientific R&D, to pure pre-market research and testing, or to purely personal non-professional use. Free and open-source AI is largely exempt unless it is a prohibited practice, a high-risk system, or a GPAI model.

Classification

The four risk tiers

The Act sorts AI uses into four bands. Most systems fall in the bottom tier and carry no mandatory obligation.

Tier 1 · Unacceptable

Prohibited (Art. 5)

Banned outright since 2 Feb 2025.

Examples: social scoring, manipulative/subliminal techniques, untargeted facial-image scraping, emotion inference at work or school, most real-time public biometric identification.
Tier 2 · High risk

Full obligations (Art. 8–27)

Annex I safety components + Annex III use cases.

Examples: CV-screening & recruitment, credit scoring, insurance pricing, biometrics, critical-infrastructure safety, education assessment, law enforcement.
Tier 3 · Limited risk

Transparency (Art. 50)

Disclosure duties, not the full regime.

Examples: chatbots (tell users it's AI), deepfakes and synthetic media (label/mark), emotion-recognition notice.
Tier 4 · Minimal risk

No mandatory duty

The vast majority of systems.

Examples: spam filters, AI in games, recommenders, inventory optimisation, grammar assistants. Voluntary codes encouraged.
One duty spans all tiers. AI literacy (Art. 4) — ensuring staff who build or use AI have adequate skills and understanding — applies to every provider and deployer, regardless of risk tier, since 2 Feb 2025.
Foundation models

General-purpose AI (GPAI) & systemic-risk models

GPAI models are a separate, cross-cutting category (Title V) layered on top of the four tiers. A general-purpose AI model shows significant generality and can perform a wide range of distinct tasks — the foundation/large language models behind today's chatbots and coding assistants. There are two levels of obligation:

  • All GPAI modelsArticle 53: maintain technical documentation, inform downstream integrators, adopt an EU copyright/TDM-opt-out policy, and publish a summary of training content. Open-source GPAI is exempt from some documentation duties unless it has systemic risk.
  • GPAI with systemic riskArticle 55: additional duties triggered when training compute exceeds 1025 FLOP (presumption) or by Commission designation — model evaluation, adversarial testing (red-teaming), systemic-risk mitigation, serious-incident reporting to the AI Office, and model-level cybersecurity.

A voluntary GPAI Code of Practice, facilitated by the AI Office and published in 2025, offers a presumption-of-conformity route while harmonised standards are developed. GPAI obligations have applied since 2 August 2025.

Reference

The key articles, explained

Each article below carries an anchor id so Shadow AI Discovery reports can deep-link straight to the obligation behind a finding.

Art. 5

Prohibited AI practices

All actors

Bans AI uses judged to pose unacceptable risk, applicable since 2 Feb 2025. The list covers subliminal/manipulative techniques that cause harm; exploitation of vulnerabilities (age, disability, social/economic situation); social scoring; individual crime-risk prediction from profiling alone; untargeted scraping of facial images; emotion recognition in the workplace and schools; biometric categorisation inferring sensitive attributes; and — with narrow, authorised law-enforcement exceptions — real-time remote biometric identification in public spaces.

Art. 9

Risk-management system

Provider · high-risk

Requires a continuous, iterative risk-management system across the entire lifecycle of a high-risk system: identify known and foreseeable risks; estimate risk under intended use and reasonably foreseeable misuse; evaluate post-market data; and adopt targeted risk-control measures. Residual risks must be judged acceptable, and the system must be tested against defined metrics before deployment and throughout development, with special attention to children and vulnerable groups.

Art. 10

Data and data governance

Provider · high-risk

Training, validation, and testing datasets must meet quality criteria and be governed for origin, preparation, assumptions, suitability, and examination for biases affecting health, safety, or rights. Datasets should be relevant, sufficiently representative, and as far as possible free of errors and complete for the intended purpose. Limited processing of special-category data is permitted strictly for bias detection and correction, with safeguards.

Art. 12

Record-keeping (logging)

Provider · Deployer

High-risk systems must automatically log events over their lifetime, to a degree appropriate to their purpose, to ensure traceability, support post-market monitoring (Art. 72), and flag situations that may present a risk or a substantial modification. Deployers must keep the logs (generally at least six months). Minimum log content is specified for certain biometric systems.

Art. 13

Transparency & instructions to deployers

Provider · high-risk

High-risk systems must be sufficiently transparent for deployers to interpret and use output appropriately, and must ship with instructions for use covering the provider's identity, intended purpose, performance and known limitations, human-oversight measures, expected lifetime, and maintenance. (Distinct from Art. 50, which is transparency to end users.)

Art. 14

Human oversight

Provider · Deployer

High-risk systems must be designed so humans can effectively oversee them in use — understanding capabilities and limits, staying alert to automation bias, correctly interpreting output, deciding not to use or to override, and being able to intervene or stop the system. For certain biometric identification, a "four-eyes" principle (verification by two competent people) applies.

Art. 50

Transparency to users & synthetic content

Provider · Deployer

Applies from 2 Aug 2026: chatbots must tell people they are dealing with an AI; generative-AI output must be marked in a machine-readable format as artificially generated; deployers must disclose deepfakes and AI-generated public-interest text; and people exposed to emotion-recognition or biometric-categorisation systems must be informed.

Art. 53

GPAI provider obligations

GPAI provider

Baseline duties for all general-purpose AI model providers: maintain up-to-date technical documentation (training/testing and evaluation); provide documentation to downstream providers; adopt a policy to comply with EU copyright law including honouring TDM opt-outs; and publish a sufficiently detailed summary of training content per the AI Office template. Open-source GPAI gets relief from some documentation duties (not the copyright and training-summary duties).

Art. 55

GPAI systemic-risk obligations

GPAI · systemic

Additional duties for GPAI models with systemic risk (≥1025 FLOP or Commission designation): perform model evaluation with standardised protocols and adversarial testing (red-teaming); assess and mitigate systemic risks and their sources; track, document, and report serious incidents to the AI Office without undue delay; and ensure an adequate level of cybersecurity for the model and its physical infrastructure.

Art. 72

Post-market monitoring

Provider · high-risk

Providers must establish a post-market monitoring system proportionate to the system's risks, actively and systematically collecting, documenting, and analysing performance data over the lifetime — feeding back into the Art. 9 risk process. Serious incidents are separately reportable under Art. 73.

Art. 25 & 26

Deployer obligations (& becoming a provider)

Deployer

Art. 26 sets deployer duties for high-risk systems: use the system per the provider's instructions, assign competent human oversight, ensure input data is relevant, keep logs, inform affected workers and persons, and cooperate with authorities. Art. 25 is the trap: put your name on a high-risk system, substantially modify it, or change its intended purpose so it becomes high-risk, and you inherit the full provider obligation set.

Annexes

Annex III & Annex IV

Annex III — high-risk use cases

Lists the domains that make a stand-alone AI system high-risk (subject to the Art. 6(3) "no significant risk" filter):

  • Biometrics — remote identification, sensitive-attribute categorisation, emotion recognition.
  • Critical infrastructure — safety components for traffic, water, gas, heating, electricity, digital infrastructure.
  • Education & vocational training — admissions, learning-outcome evaluation, exam monitoring.
  • Employment — recruitment/selection (CV screening, ranking), promotion, termination, task allocation, performance monitoring.
  • Essential private & public services — benefits eligibility, creditworthiness/credit scoring, life & health insurance risk & pricing, emergency triage.
  • Law enforcement — risk assessment, polygraph-type tools, evidence-reliability evaluation, profiling.
  • Migration, asylum & border control — risk assessment, application examination.
  • Administration of justice & democratic processes — assisting judicial authorities; influencing elections/voting.

Annex IV — technical documentation

Specifies the contents of the technical-documentation file a high-risk provider must compile and keep current: a general description and intended purpose; design specifications, architecture, and development process; data requirements and datasets; human-oversight measures; validation/testing procedures and metrics (accuracy, robustness, cybersecurity, bias results); the risk-management system; lifecycle changes; and the EU declaration of conformity. This is the evidence file behind the CE marking.

Duties

Obligations by role

If you build or brand the AI, you're a provider and carry most obligations. If you use AI from someone else, you're a deployer. Watch Art. 25 for role flips.

Obligation areaProvider (high-risk)Deployer (high-risk)Importer / Distributor
Risk management (Art. 9)Build & maintainFeed monitoring back
Data governance (Art. 10)YesRelevant input data
Technical docs (Annex IV)CompileKeep instructions/logsVerify present
Logging (Art. 12)Design inKeep logs ≥6mo
Instructions & oversight (Art. 13/14)Provide/designFollow & staffCheck accompanied
Conformity + CE (Art. 43/47/48)YesVerify marks
Deployer duties (Art. 26)Yes
Fundamental-rights impact (Art. 27)Certain deployers
AI literacy (Art. 4)YesYesYes
GPAI duties (Art. 53/55)GPAI providersRely on upstream docs
Deadlines

The compliance timeline

1 Aug 2024
Entry into force. The Regulation becomes law across the EU.
2 Feb 2025
Prohibited practices (Art. 5) and AI-literacy (Art. 4) obligations apply.
2 Aug 2025
GPAI model obligations (Art. 53/55), governance bodies, and penalties provisions apply. Pre-existing GPAI models have until 2 Aug 2027.
2 Aug 2026
General application — Annex III high-risk obligations and Art. 50 transparency apply. The near-term compliance cliff for most organisations.
2 Aug 2027
High-risk obligations for Annex I product-safety AI apply; deadline for pre-existing GPAI models.
2030
Extended deadlines for certain large-scale IT systems and specific public-sector legacy systems.
Enforcement

Penalties

Fines are capped at the higher of a fixed amount or a percentage of total worldwide annual turnover (for SMEs/start-ups, the lower). National authorities enforce most breaches; the Commission's AI Office enforces GPAI directly.

BreachMaximum fine
Prohibited practices (Art. 5)€35M or 7% of global annual turnover
Most other obligations (high-risk, transparency, provider/deployer duties)€15M or 3% of global annual turnover
Incorrect/misleading information to authorities€7.5M or 1% of global annual turnover
GPAI providers (Commission-enforced)€15M or 3% of global annual turnover
Practical

How to comply — a working checklist

  • Inventory & classify. Build a live inventory of every AI system — sanctioned and shadow — and record your role and each system's intended purpose. Screen against Art. 5, Annex I/III, Art. 50, and the GPAI definition.
  • Cover what's already in force. Confirm no prohibited practices; stand up an AI-literacy programme (Art. 4).
  • For each high-risk system (by 2 Aug 2026). Establish the Art. 9 risk-management system, evidence Art. 10 data governance, compile Annex IV docs, enable Art. 12 logging, provide Art. 13 instructions and Art. 14 oversight, meet Art. 15 accuracy/robustness/cybersecurity, run the Art. 43 conformity assessment, draw up the Art. 47 declaration, affix CE marking, and register (Art. 71).
  • For limited-risk (by 2 Aug 2026). Add AI-disclosure to chatbots; mark synthetic content and label deepfakes (Art. 50).
  • If you provide/self-host GPAI (now in force). Maintain Art. 53 documentation, copyright/TDM policy, and a training-content summary; add Art. 55 controls if systemic-risk.
  • Govern continuously. Monitor for re-tiering, retain evidence, rehearse incident reporting, and map controls to NIST AI RMF, ISO/IEC 42001, and the OWASP LLM Top 10 to reuse evidence.
Where Shadow AI Discovery fits. The sensor produces the inventory, role assignment, and much of the evidence (logging state, key exposure, red-team telemetry) that the Art. 9, Art. 55, and Annex IV obligations demand — auto-mapped to the article set on this page.
Reference

Glossary

AI system
Machine-based system with autonomy that infers outputs from inputs (Art. 3(1)).
AI Office
The Commission body overseeing GPAI and coordinating implementation.
Annex III
List of high-risk use-case domains for stand-alone AI systems.
Annex IV
Required contents of the technical-documentation file.
CE marking
Conformity marking affixed after a successful conformity assessment (Art. 48).
Conformity assessment
Process proving a high-risk system meets the requirements (Art. 43).
Deployer
Entity using an AI system under its authority, professionally.
Deepfake
AI-generated/manipulated media that would falsely appear authentic.
GPAI model
General-purpose (foundation) model usable across many downstream tasks.
FLOP
Floating-point operations; ≥1025 FLOP presumes systemic risk.
FRIA
Fundamental-rights impact assessment for certain deployers (Art. 27).
Provider
Entity that develops and places an AI system/GPAI model on the market under its own name.
Serious incident
Incident leading to death, serious harm, critical-infrastructure disruption, or rights breach (Art. 73).
Systemic risk
Risk from high-impact GPAI capabilities with significant EU-market effect (Art. 51).
TDM opt-out
Text-and-data-mining rights reservation that GPAI training must respect.
Sources

Official references

Not legal advice. This explainer is a working reference for security and compliance teams, not a legal opinion. Specific classifications and obligations should be validated with qualified counsel. Accurate as of 2025–2026; the Act and its guidance continue to evolve.