AI Act

The EU AI Act, in operational terms

The AI Act is the world's first comprehensive regulatory framework for artificial intelligence. This is our practical reading: what applies, when, to whom, and what you must be able to demonstrate.

Email updates

Get AI Act updates by email

Practical updates on the EU AI Act: deadlines, Article 50 transparency, guidance and enforcement. Low volume, no marketing.

Double opt-in: we only send updates after you confirm. You can unsubscribe from any email. See our privacy policy.

Timeline

Application timeline

  1. 1 Aug 2024

    Entry into force

    The Regulation enters into force and the staggered application timeline begins.

  2. 2 Feb 2025

    Prohibited practices

    Bans on unacceptable uses apply, together with AI literacy obligations.

  3. 2 Aug 2025

    General-purpose AI models

    Obligations for GPAI providers, plus governance and penalty structures.

  4. 2 Aug 2026

    General application & enforcement

    The AI Office and national market surveillance authorities begin enforcing the Regulation. Annex III high-risk systems and the Article 50 transparency obligations apply.

  5. 2 Aug 2027

    High risk in regulated products

    AI systems embedded in products covered by EU sectoral legislation.

Risk

Risk tiers

01

Unacceptable risk

Prohibited practices: harmful manipulation, social scoring, sensitive biometric categorisation and other banned uses.

02

High risk

Employment, education, essential services, critical infrastructure, justice, migration and biometrics. Requires risk management, data governance, technical documentation, registration, human oversight and conformity assessment.

03

Transparency risk

Chatbots, synthetic content and emotion recognition: duty to inform users and label content.

04

Minimal risk

Everything else. No specific obligations, but voluntary good practice applies.

Transparency

Article 50: transparency from 2 August 2026

Article 50 applies from 2 August 2026. It splits the duties between whoever builds the system (the provider) and whoever uses it under their own authority (the deployer).

Provider obligations

  • Design the system so that individuals are explicitly informed whenever they interact directly with an AI system.
  • Add machine-readable marks that allow AI-generated or manipulated content to be detected.
  • Make marking solutions effective, interoperable, robust and reliable as far as technically feasible.

Deployer obligations

  • Inform individuals when emotion recognition or biometric categorisation is used.
  • Disclose that image, audio or video content is a deepfake.
  • Disclose AI-generated text published on matters of public interest where there was no human review or editorial control.

How compliance is demonstrated

Code of Practice on transparency

The Commission published a first list of more than 180 organisations that signed the Code of Practice on transparency of AI-generated content, which operationalises these obligations.

Not adhering means finding equivalent means

Providers and deployers that do not adhere to the Code must demonstrate marking and labelling through alternative, equivalently adequate means. For the other transparency obligations, each organisation determines adequate measures itself, taking the Guidelines into account.

Who supervises

National market surveillance authorities, the AI Office for systems under its supervision, and the European Data Protection Supervisor where EU institutions are providers or deployers.

This content is informational and reflects our technical reading of the Regulation and published guidance. It is not legal advice.

Evidence

What you must be able to demonstrate

  • A reasoned classification of the system and of your role (provider, deployer, importer or distributor).
  • A living risk management system, not a one-off document.
  • Data governance: provenance, quality, representativeness and bias.
  • Technical documentation retained and available for ten years.
  • Automatic event logs that allow the system's behaviour to be reconstructed.
  • Effective human oversight and trained staff.
  • Change control over substantial modifications, including swapping the underlying model.

Two points that are usually missed

You can be a 'provider' without selling anything

If you develop a high-risk AI system and put it into service internally under your own name, you take on provider obligations.

Changing the model can be a substantial modification

Replacing the underlying model or altering the intended purpose can reopen the conformity assessment.

This content is informational and reflects our technical reading of the Regulation and published guidance. It is not legal advice.

Checklist

EU AI Act compliance checklist

A practical starting point, not a 50-item questionnaire: twelve questions grouped by control area. Any answer you cannot support with evidence is where your compliance work begins.

Governance

  • Have you identified whether you are a provider, a deployer, or both?
  • Have you defined the intended purpose of each AI system?

Risk assessment

  • Have you classified the risk level of each of your AI systems?
  • Have you documented the reasoning behind that classification?

Transparency

  • Do you clearly inform users when they are interacting with an AI system?
  • Do you label synthetic content where the Regulation requires it?

Human oversight

  • Is there human review before the system produces legally or materially relevant effects?
  • Is that oversight documented, with named roles and intervention powers?

Organisation

  • Do you maintain an inventory of the AI systems in use across the organisation?
  • Have you trained your staff in the responsible use of AI (AI literacy)?

Documentation

  • Do you keep technical documentation and event logs up to date and retrievable?
  • Do you periodically review your systems, models and third-party suppliers?

Coming soon: a downloadable, extended version of this checklist.

This content is informational and reflects our technical reading of the Regulation and published guidance. It is not legal advice.

Interactive

Which obligations apply to you?

Select your situation. The tool gathers the obligations and articles to review first. It is orientation, not a conformity assessment.

Select everything that applies

You should review

Select at least one option to see the applicable obligations.

Informational orientation. Not legal advice and not a conformity assessment.

FAQ

Frequently asked questions

What changed on 2 August 2026?

The Commission, through the AI Office, and national authorities began enforcing the Regulation. The Article 50 transparency obligations and the Annex III high-risk regime also started to apply.

Who has to label AI-generated content?

The provider must embed machine-readable marks in synthetic content. The deployer must disclose deepfakes, emotion recognition, biometric categorisation, and text on matters of public interest published without human review.

Do chatbots have to say they are AI?

Yes. Systems that interact directly with people must be designed so the person is explicitly informed they are dealing with AI, unless this is obvious to a reasonably well-informed user.

Does signing the transparency Code of Practice guarantee compliance?

Not on its own, but it is the recognised route to demonstrate marking and labelling. Those who do not adhere must demonstrate it through alternative, equivalently adequate means.

Who enforces these rules?

National market surveillance authorities, the AI Office for systems under its supervision, and the European Data Protection Supervisor where EU institutions are involved. Complaints and whistleblower channels are also available.

What is still pending after 2026?

From 2 August 2027, obligations apply to high-risk systems embedded in products covered by EU sectoral legislation, with their own conformity assessment procedures.

This content is informational and reflects our technical reading of the Regulation and published guidance. It is not legal advice.

From regulatory text to infrastructure

We help institutions and enterprises classify their systems, build the technical file and demonstrate compliance continuously.