AI Act

The EU AI Act, in operational terms

The AI Act is the world's first comprehensive regulatory framework for artificial intelligence. This is our practical reading: what applies, when, to whom, and what you must be able to demonstrate.

Timeline

Application timeline

  1. 1 Aug 2024

    Entry into force

    The Regulation enters into force and the staggered application timeline begins.

  2. 2 Feb 2025

    Prohibited practices

    Bans on unacceptable uses apply, together with AI literacy obligations.

  3. 2 Aug 2025

    General-purpose AI models

    Obligations for GPAI providers, plus governance and penalty structures.

  4. 2 Aug 2026

    General application

    The bulk of the Regulation applies, including Annex III high-risk systems and transparency obligations.

  5. 2 Aug 2027

    High risk in regulated products

    AI systems embedded in products covered by EU sectoral legislation.

Risk

Risk tiers

01

Unacceptable risk

Prohibited practices: harmful manipulation, social scoring, sensitive biometric categorisation and other banned uses.

02

High risk

Employment, education, essential services, critical infrastructure, justice, migration and biometrics. Requires risk management, data governance, technical documentation, registration, human oversight and conformity assessment.

03

Transparency risk

Chatbots, synthetic content and emotion recognition: duty to inform users and label content.

04

Minimal risk

Everything else. No specific obligations, but voluntary good practice applies.

Evidence

What you must be able to demonstrate

  • A reasoned classification of the system and of your role (provider, deployer, importer or distributor).
  • A living risk management system, not a one-off document.
  • Data governance: provenance, quality, representativeness and bias.
  • Technical documentation retained and available for ten years.
  • Automatic event logs that allow the system's behaviour to be reconstructed.
  • Effective human oversight and trained staff.
  • Change control over substantial modifications, including swapping the underlying model.

Two points that are usually missed

You can be a 'provider' without selling anything

If you develop a high-risk AI system and put it into service internally under your own name, you take on provider obligations.

Changing the model can be a substantial modification

Replacing the underlying model or altering the intended purpose can reopen the conformity assessment.

This content is informational and reflects our technical reading of the Regulation and published guidance. It is not legal advice.

From regulatory text to infrastructure

We help institutions and enterprises classify their systems, build the technical file and demonstrate compliance continuously.