EU AI Act guide

The EU AI Act: a citation-grounded guide for operators

Regulation (EU) 2024/1689 entered into force on 1 August 2024 and applies in phases through August 2028, with the Annex III high-risk wave deferred to 2 December 2027 under the Digital Omnibus, adopted 29 June 2026. This guide walks through scope, risk tiers, prohibited practices, high-risk obligations, timelines and penalties — every claim cites a specific Article or Annex of the regulation.

Last updated 2 July 2026, reflecting the EU's Digital Omnibus, adopted 29 June 2026.

Last reviewed: 4 July 2026

Every claim in this guide cites an Article or Annex of Regulation (EU) 2024/1689. Cross-check against EUR-Lex and the EU AI Act Service Desk before acting.

What is the EU AI Act?

The EU AI Act is Regulation (EU) 2024/1689 of the European Parliament and of the Council, published in the Official Journal of the European Union on 12 July 2024 and in force since 1 August 2024 (Article 113). It is the first horizontal, binding law governing artificial intelligence systems placed on the Union market, put into service in the Union, or whose output is used in the Union.

The regulation pursues two stated objectives: (a) to ensure that AI systems placed on the Union market and used in the Union are safe and respect fundamental rights and Union values; and (b) to support innovation, including a functioning internal market for lawful, trustworthy AI. The legal basis combines Article 114 TFEU (internal market) with Article 16 TFEU (data protection), which is why the Act applies uniformly across all Member States rather than leaving discretion at national level.

The Act does not replace sectoral law. Where existing legislation already addresses risks — for example, the Medical Device Regulation (MDR), the Machinery Regulation, or financial services governance rules such as MiFID II and the CRD — those regimes continue to apply and the AI Act adds layered requirements where relevant (Article 2(6); Annex I).

Territorial and personal scope

Article 2(1) sets a deliberately broad reach. The Act applies to: providers placing AI systems on the Union market or putting them into service in the Union, regardless of where those providers are established; deployers of AI systems that have their place of establishment in the Union; and, critically, providers and deployers established outside the Union where the output produced by the AI system is used in the Union. This last limb means a non-EU SaaS vendor whose scoring engine is consulted by an EU bank is in scope, even if the vendor has no EU office.

Several carve-outs exist. AI systems developed or used exclusively for military, defence or national security purposes are outside scope (Article 2(3)). Systems used solely for scientific research and development are excluded until placement on the market (Article 2(6)). Purely personal non-professional activity by natural persons is excluded (Article 2(10)). Free and open-source AI systems are excluded unless they are placed on the market or put into service as high-risk systems, prohibited systems, or systems subject to Article 50 transparency obligations (Article 2(12)).

The Article 4 AI literacy duty has applied to every provider and deployer since 2 February 2025; an AI literacy template helps you evidence it. If you run critical infrastructure, also check your NIS2 exposure with the NIS2 checker.

The risk-based framework

The Act organises obligations around four risk tiers. Classification determines which rules apply, which deadlines bind, and which penalties are in reach.

  1. Unacceptable risk (prohibited)

    Article 5

    Eight practices are banned outright because they are incompatible with Union values. They have been unenforceable since 2 February 2025 (Article 113(a)). Violations carry the heaviest fines under the Act.

  2. High-risk

    Articles 6–27, Annex I and Annex III

    Two pathways qualify. Annex I covers AI systems that are safety components of, or are themselves, products already regulated by listed Union harmonisation law (for example medical devices, machinery, toys) and that require third-party conformity assessment. Annex III lists eight stand-alone domains — biometrics, critical infrastructure, education, employment, essential private and public services, law enforcement, migration, and the administration of justice and democratic processes. High-risk providers and deployers shoulder the bulk of the Act's substantive obligations.

  3. Limited risk (transparency)

    Article 50

    Systems that interact with natural persons, perform emotion recognition or biometric categorisation, generate synthetic content, or produce deepfakes must disclose that an AI is involved. No conformity assessment, no registration — but the disclosure must be clear, accessible, and, for synthetic media, machine-readable.

  4. Minimal risk

    Article 95

    Everything else. No mandatory obligations. The Commission and the AI Office encourage voluntary codes of conduct, and Article 4 AI-literacy duties still apply to staff using any AI system.

Limited-risk systems face the Article 50 transparency duties from 2 August 2026. Use the Article 50 transparency checker to see which disclosures apply to your system.

Prohibited practices

Article 5(1) prohibits eight classes of AI practice. Each prohibition has defined elements and, in most cases, narrow carve-outs. The list below summarises each in one line — the regulation itself remains the binding reference.

  • Art. 5(1)(a)

    Subliminal, purposefully manipulative or deceptive techniques that materially distort behaviour and cause or are likely to cause significant harm.

  • Art. 5(1)(b)

    Exploitation of the vulnerabilities of a natural person or group (age, disability, specific social or economic situation) that materially distorts behaviour and causes or is likely to cause significant harm.

  • Art. 5(1)(c)

    Social scoring by public authorities or on their behalf leading to detrimental or disproportionate treatment in contexts unrelated to the data used.

  • Art. 5(1)(d)

    Predictive policing of individual natural persons based solely on profiling or personality traits, except when used to augment human assessment grounded in objective facts directly linked to criminal activity.

  • Art. 5(1)(e)

    Untargeted scraping of facial images from the internet or CCTV footage to create or expand facial recognition databases.

  • Art. 5(1)(f)

    Emotion recognition in the workplace and in education institutions, except where strictly necessary for medical or safety reasons.

  • Art. 5(1)(g)

    Biometric categorisation that infers race, political opinions, trade union membership, religious or philosophical beliefs, sex life or sexual orientation; law enforcement may lawfully label or filter biometric data already acquired in line with Union law.

  • Art. 5(1)(h)

    Real-time remote biometric identification in publicly accessible spaces for law enforcement, subject to three narrow exceptions in Article 5(1)(h)(i)–(iii) and prior judicial or administrative authorisation under Article 5(3).

The prohibitions have applied since 2 February 2025 (Article 113(a)). Infringements can attract administrative fines of up to €35 million or 7 % of worldwide annual turnover, whichever is higher (Article 99(3)).

High-risk AI systems: Annex III domains

Annex III lists eight stand-alone domains in which an AI system is classified as high-risk because the Union legislator considers it capable of significantly affecting health, safety, or fundamental rights. The list can be expanded or amended by the Commission under Article 7.

  1. 1. Biometrics

    Annex III point 1

    Remote biometric identification outside the real-time public-space carve-out that is prohibited under Article 5(1)(h); biometric categorisation by sensitive or protected attributes; emotion recognition systems, where not prohibited under Article 5(1)(f).

  2. 2. Critical infrastructure

    Annex III point 2

    AI used as a safety component in the management and operation of critical digital infrastructure, road traffic, and the supply of water, gas, heating and electricity. The system must be a safety component in the legal sense — general-purpose back-office software used by a utility is not automatically covered.

  3. 3. Education and vocational training

    Annex III point 3

    Systems that determine access, admission, or assignment to educational institutions; evaluate learning outcomes and steer learning; assess the appropriate level of education for a natural person; or monitor and detect prohibited behaviour during exams.

  4. 4. Employment, workers management and access to self-employment

    Annex III point 4

    Recruitment tooling — targeted job advertising, screening or filtering applications, evaluating candidates — and decisions affecting work relationships such as promotion, termination, task allocation based on individual behaviour or traits, and monitoring and evaluating performance.

  5. 5. Access to essential private and public services

    Annex III point 5

    Evaluating eligibility for public assistance benefits and services (including healthcare) by or on behalf of public authorities; evaluating the creditworthiness of natural persons or establishing their credit score, other than systems used exclusively to detect financial fraud; risk assessment and pricing for life and health insurance; evaluating and classifying emergency calls and dispatching emergency services.

  6. 6. Law enforcement

    Annex III point 6

    Systems used by or on behalf of law enforcement to assess the risk of a natural person becoming the victim of a criminal offence; polygraphs and similar tools; evaluating the reliability of evidence; assessing the risk of offending or re-offending (other than as prohibited under Article 5(1)(d)); and profiling in the course of detection, investigation or prosecution.

  7. 7. Migration, asylum and border control

    Annex III point 7

    Polygraphs used in migration contexts; assessing risks posed by natural persons intending to enter Union territory (including health risks); examining applications for asylum, visa or residence permits and the associated complaints; detecting, recognising or identifying natural persons in migration contexts, with a carve-out for travel document verification.

  8. 8. Administration of justice and democratic processes

    Annex III point 8

    Systems intended to assist judicial authorities in researching and interpreting facts and the law and in applying it to concrete facts, including in alternative dispute resolution; and systems intended to influence the outcome of an election or referendum or the voting behaviour of natural persons, with a carve-out for back-office tools that do not directly interact with voters.

Beyond Annex III, Article 6(1) classifies an AI system as high-risk if it is a safety component of, or itself, a product that is covered by Union harmonisation legislation listed in Annex I and that product is required to undergo third-party conformity assessment. This pathway is the route by which AI in medical devices, machinery, toys, lifts, radio equipment and similar sector-specific products is picked up. Under the Digital Omnibus, adopted 29 June 2026, Annex I high-risk obligations apply from 2 August 2028, eight months after the Annex III deadline of 2 December 2027.

Providers of high-risk systems must produce concrete evidence: a risk management system under Article 9 (template), the Annex IV technical documentation (template), and, where applicable, a fundamental rights impact assessment under Article 27 (FRIA template).

The Article 6(3) exception

An AI system that matches an Annex III entry is not classified as high-risk where the provider documents that it does not pose a significant risk of harm to the health, safety or fundamental rights of natural persons, including by not materially influencing the outcome of decision-making. Article 6(3) sets out four narrow conditions and a profiling override.

  • The system performs a narrow procedural task (Article 6(3)(a)).
  • The system improves the result of a previously completed human activity (Article 6(3)(b)).
  • The system detects decision-making patterns or deviations from prior decision-making patterns and is not meant to replace or influence the human assessment without proper human review (Article 6(3)(c)).
  • The system performs a preparatory task to an assessment relevant for the purposes listed in Annex III (Article 6(3)(d)).

Article 6(3) second subparagraph contains an override: an Annex III system is always high-risk when it performs profiling of natural persons within the meaning of Article 4(4) GDPR. Profiling is any automated processing of personal data to evaluate personal aspects of a natural person, including performance at work, economic situation, health, preferences, reliability, behaviour, location or movements. If profiling is present, the four conditions above do not rescue the system from high-risk status.

Even where the exception applies, the provider must document the assessment supporting that conclusion (Article 6(4)) and register the system in the EU database with the reasoning (Article 49(2)). The market surveillance authority can request the assessment on reasoned request (Article 6(4)).

Provider and deployer obligations

The Act assigns obligations by role. A provider develops an AI system (or has one developed) and places it on the market or puts it into service under its own name or trademark (Article 3(3)). A deployer uses an AI system under its authority in the course of a professional activity (Article 3(4)). The same person can be both, for instance when a company builds an internal tool for its own use.

Provider obligations (Article 16 and following)

For high-risk systems, Article 16 summarises the provider obligation catalogue: establish a risk management system throughout the lifecycle (Article 9); apply data-governance rules to training, validation and test sets (Article 10); draw up technical documentation per Annex IV before market placement and keep it up to date (Article 11); ensure automatic event logging (Article 12); supply instructions for use and other transparency information (Article 13); design human oversight measures into the system (Article 14); meet accuracy, robustness and cybersecurity requirements (Article 15); operate a quality management system (Article 17); retain documentation for ten years and logs for the period appropriate to the intended purpose, with six months as a floor (Articles 18–19); take corrective action when non-conformity is detected (Article 20); cooperate with competent authorities (Article 21); appoint an authorised representative where the provider is established outside the Union (Article 22); complete the conformity assessment under Article 43; draw up an EU declaration of conformity under Article 47; affix CE marking under Article 48; register the system in the EU database under Article 49; implement post-market monitoring under Article 72; and report serious incidents to the competent market surveillance authority under Article 73. For a deeper walk-through, see the Witness features page.

Deployer obligations (Article 26 and following)

High-risk deployers must use the system in accordance with the provider's instructions and take appropriate technical and organisational measures to ensure that (Article 26(1)); assign human oversight to competent, trained and authorised natural persons (Article 26(2)); ensure that input data they control is relevant and sufficiently representative of the intended purpose (Article 26(4)); monitor operation, suspend use when risks arise, inform the provider or distributor and report serious incidents (Article 26(5)); retain automatically generated logs for at least six months where within their control (Article 26(6)); inform workers' representatives and affected workers before deploying a high-risk system in the workplace (Article 26(7)); inform natural persons subject to AI-assisted decisions that have legal or similarly significant effects on them (Article 26(11)); and, where the system is used for emotion recognition or biometric categorisation, inform exposed persons (Article 50(3)). Deployers that are public authorities, private entities providing public services, or deployers of Annex III point 5(b) creditworthiness systems or point 5(c) life- and health-insurance pricing systems must additionally perform a Fundamental Rights Impact Assessment under Article 27 before first use.

When a deployer becomes a provider

Article 25(1) identifies three triggers that turn a distributor, importer, deployer or other third party into a provider, with the full provider obligation catalogue attached: (a) putting their name or trademark on a high-risk system already placed on the market; (b) making a substantial modification to a high-risk system; or (c) modifying the intended purpose of an AI system in a way that brings it within the high-risk classification. Fine-tuning an existing model to change its intended purpose is the most common way an operator unwittingly walks into provider duties.

General-purpose AI models (Articles 51–56)

Providers of general-purpose AI models have their own regime. Article 53 imposes baseline duties: maintain Annex XI technical documentation, share Annex XII information with downstream providers, implement a copyright compliance policy aligned with Article 4(3) of Directive (EU) 2019/790, and publish a sufficiently detailed summary of training content using the AI Office template. Providers of GPAI models presenting systemic risk — the compute-based presumption bites at a cumulative training compute greater than 10²⁵ FLOPs (Article 51(2)) — face additional obligations under Article 55, including model evaluations, systemic risk mitigation and serious-incident reporting to the AI Office.

A walk-through of each module lives on the features page.

Application timeline

Article 113 staggers the application of the Act, and the Digital Omnibus, adopted 29 June 2026, further defers the high-risk waves. The Omnibus enters into force upon publication in the Official Journal (expected July 2026). Mark the dates that apply to your role and risk tier. Article 50(2) transparency obligations remain on the original 2 August 2026 date; the Omnibus does not move them.

EU AI Act application timeline
DateMilestoneLegal basisWhat applies
2 February 2025Prohibitions and AI literacyArticle 113(a)Article 5 prohibitions and Article 4 AI-literacy obligations became applicable. Every provider and deployer must ensure that staff dealing with AI systems have a level of AI literacy appropriate to their role, context and to the persons affected.
2 August 2025GPAI obligations, governance, penaltiesArticle 113(b)Chapter V (general-purpose AI models, Articles 51–56), Chapter III Section 4 (notifying authorities, Articles 28–39), Chapter VII Part 1 (governance, Articles 64–70) and Chapter XII (penalties, Articles 99–101) became applicable.
2 August 2026Article 50(2) transparency obligationsArticle 113; Article 50Article 50 transparency duties apply: chatbots and AI-interaction disclosures, deepfake labelling, machine-readable marking of synthetic audio, image, video and text content, and emotion-recognition / biometric-categorisation notices. The Omnibus does not move this wave.
2 December 2026New Article 5 prohibition (non-consensual sexual content, CSAM)Digital Omnibus, adopted 29 June 2026A new Article 5 prohibition added by the Digital Omnibus banning AI generation of non-consensual sexual or intimate content and child sexual abuse material applies from this date, four months after the transparency wave.
2 August 2027National AI regulatory sandboxesArticle 57Each Member State must have at least one operational AI regulatory sandbox in place by this date, providing a controlled environment for SMEs and start-ups to develop, test and validate innovative AI systems under regulatory oversight before market placement.
2 December 2027Annex III high-risk obligations (Omnibus-deferred)Article 113; Digital Omnibus, adopted 29 June 2026The bulk of the high-risk regime applies: Annex III provider and deployer obligations (Articles 6–27), Article 43 conformity assessment, Article 49 EU-database registration, Article 27 FRIA obligations, and post-market monitoring and incident reporting duties under Articles 72–73. Originally set for 2 August 2026; deferred by the Digital Omnibus, adopted 29 June 2026.
2 August 2028Annex I product-embedded AI and GPAI transitionalArticle 113(c); Article 111(3); Digital Omnibus, adopted 29 June 2026Article 6(1) high-risk systems — AI embedded in products covered by Annex I Union harmonisation law that require third-party conformity assessment — become fully subject to the Act. General-purpose AI models already placed on the market before 2 August 2025 must be brought into compliance by this date (Article 111(3)). Originally set for 2 August 2027; deferred by the Digital Omnibus, adopted 29 June 2026.

Penalties

Article 99 sets a three-tier fine structure. Member States must also provide for other non-monetary measures such as warnings and may add further penalties; these national catalogues were notified to the Commission by 2 August 2025 (Article 99(1)).

EU AI Act penalty tiers under Article 99
Maximum fineLegal basisApplies to
€35 million or 7 %Article 99(3)For non-compliance with the Article 5 prohibitions, the fine is up to €35 million or, if the offender is a company, up to 7 % of its total worldwide annual turnover for the preceding financial year, whichever is higher.
€15 million or 3 %Article 99(4); Article 101For non-compliance with provider, deployer, notified body and authorised representative obligations, the fine is up to €15 million or up to 3 % of worldwide annual turnover, whichever is higher. Providers of general-purpose AI models are fined under a separate regime: the European Commission may impose fines up to the same caps under Article 101, applicable from 2 August 2026.
€7.5 million or 1 %Article 99(5)For supplying incorrect, incomplete or misleading information to notified bodies or national competent authorities, the fine is up to €7.5 million or up to 1 % of worldwide annual turnover, whichever is higher.

For SMEs, including start-ups, Article 99(6) reverses the rule: the lower of the fixed cap and the percentage cap applies, which meaningfully limits exposure for smaller operators. EU institutions, bodies, offices and agencies face separate, lower caps under Article 99(8), administered by the European Data Protection Supervisor.

You can estimate your own maximum fine exposure with the penalty calculator.

Next steps for operators

If you are unsure where your AI system sits in this framework, start with the free Witness classifier. It walks through Article 3(1), the Article 2 exclusions, each Article 5 prohibition, every Annex III area, the Article 6(3) exception including the profiling override, and the Article 50 transparency triggers. Every answer cites the article it rests on, so the reasoning is auditable. From the classifier result you can move straight into Annex IV technical documentation, Article 9 risk management, Article 27 FRIA (where required) and Article 4 AI-literacy records.

Deep dives

Frequently asked questions

Is the EU AI Act already in force?

Yes. Regulation (EU) 2024/1689 entered into force on 1 August 2024 (Article 113). Different parts of the Act apply in stages. The Article 5 prohibitions and Article 4 AI-literacy duties have been applicable since 2 February 2025. General-purpose AI model rules, notifying authorities, governance and penalties apply from 2 August 2025. Article 50(2) transparency duties apply from 2 August 2026. Under the Digital Omnibus, adopted 29 June 2026, the Annex III high-risk regime — high-risk obligations, FRIA, conformity assessment and EU-database registration — applies from 2 December 2027, and Annex I product-embedded AI obligations apply from 2 August 2028. A new Article 5 prohibition on AI-generated non-consensual sexual content and CSAM applies from 2 December 2026.

My company is outside the EU. Can we still be in scope?

Yes. Article 2(1)(c) extends the Act to providers and deployers established in a third country where the output produced by the AI system is used in the Union. A non-EU SaaS vendor whose model is consulted by an EU deployer is caught even with no European establishment. Article 22 then requires non-EU providers of high-risk systems to appoint an authorised representative in the Union by written mandate.

How do I know my system is high-risk?

There are two pathways. Under Article 6(1) the system is high-risk if it is a safety component of, or is itself, a product covered by Union harmonisation law listed in Annex I that requires third-party conformity assessment. Under Article 6(2) the system is high-risk if it falls into one of the eight Annex III domains. If Annex III is matched, check whether the Article 6(3) exception applies — four narrow functions and a profiling override. If the system profiles natural persons in the sense of Article 4(4) GDPR, the exception does not rescue it.

What does the Article 6(3) exception actually protect?

Article 6(3) protects Annex III systems whose role is limited to a narrow procedural task, improving the result of a prior human activity, detecting patterns or deviations without replacing human assessment, or performing preparatory work for a human decision. Even where the exception applies, the provider must document the assessment (Article 6(4)) and register the system in the EU database with the supporting reasoning (Article 49(2)). The exception is not silent — it is a paper-trail obligation in its own right.

What does the AI Act mean for GDPR compliance?

The AI Act operates alongside GDPR, not in place of it. Recital 10 is explicit: the Act applies without prejudice to the fundamental right to the protection of personal data, including as regulated by Regulation (EU) 2016/679. A Data Protection Impact Assessment under Article 35 GDPR may be required in addition to a Fundamental Rights Impact Assessment under Article 27 of the AI Act; Article 27(4) allows the FRIA to complement rather than duplicate an existing DPIA.

What counts as a substantial modification?

Article 3(23) defines a substantial modification as a change to an AI system after placing on the market or putting into service that was not foreseen or planned in the initial conformity assessment by the provider and that affects compliance with Chapter III Section 2 or modifies the intended purpose. Substantial modifications trigger a fresh conformity assessment under Article 43(4) and, for deployers and other third parties, can trigger the role shift in Article 25(1)(b) that turns the modifier into a provider.

Do SMEs get any relief?

Some. The third subparagraph of Article 11(1) allows SMEs, including start-ups, to provide the Annex IV technical documentation elements in a simplified manner, using a simplified form to be established by the Commission — a right that applies to all high-risk systems, not only Annex I products. Article 62 requires Member States to give SMEs and start-ups priority access to regulatory sandboxes. And Article 99(6) reverses the fine rule for SMEs: the lower of the fixed cap and the percentage cap applies, rather than the higher, meaningfully capping exposure for smaller operators.

Where can I read the binding text?

The consolidated text is published on EUR-Lex under ELI reg/2024/1689. Operational guidance and Commission templates appear on the AI Act Service Desk run by the European Commission. Both are linked at the foot of this page. This guide is a summary; where the summary and the regulation diverge, the regulation governs.

Primary sources