AI Act
The EU AI Act, in operational terms
The AI Act is the world's first comprehensive regulatory framework for artificial intelligence. This is our practical reading: what applies, when, to whom, and what you must be able to demonstrate.
Timeline
Application timeline
- 1 Aug 2024
Entry into force
The Regulation enters into force and the staggered application timeline begins.
- 2 Feb 2025
Prohibited practices
Bans on unacceptable uses apply, together with AI literacy obligations.
- 2 Aug 2025
General-purpose AI models
Obligations for GPAI providers, plus governance and penalty structures.
- 2 Aug 2026
General application
The bulk of the Regulation applies, including Annex III high-risk systems and transparency obligations.
- 2 Aug 2027
High risk in regulated products
AI systems embedded in products covered by EU sectoral legislation.
Risk
Risk tiers
Unacceptable risk
Prohibited practices: harmful manipulation, social scoring, sensitive biometric categorisation and other banned uses.
High risk
Employment, education, essential services, critical infrastructure, justice, migration and biometrics. Requires risk management, data governance, technical documentation, registration, human oversight and conformity assessment.
Transparency risk
Chatbots, synthetic content and emotion recognition: duty to inform users and label content.
Minimal risk
Everything else. No specific obligations, but voluntary good practice applies.
Evidence
What you must be able to demonstrate
- A reasoned classification of the system and of your role (provider, deployer, importer or distributor).
- A living risk management system, not a one-off document.
- Data governance: provenance, quality, representativeness and bias.
- Technical documentation retained and available for ten years.
- Automatic event logs that allow the system's behaviour to be reconstructed.
- Effective human oversight and trained staff.
- Change control over substantial modifications, including swapping the underlying model.
Two points that are usually missed
You can be a 'provider' without selling anything
If you develop a high-risk AI system and put it into service internally under your own name, you take on provider obligations.
Changing the model can be a substantial modification
Replacing the underlying model or altering the intended purpose can reopen the conformity assessment.
This content is informational and reflects our technical reading of the Regulation and published guidance. It is not legal advice.
From regulatory text to infrastructure
We help institutions and enterprises classify their systems, build the technical file and demonstrate compliance continuously.
