Regulation (EU) 2024/1689 · updated after the Digital Omnibus

The EU AI Act: what it is, who it applies to, and what you must do

The EU AI Act is the European Union's law on artificial intelligence. It sorts every AI system into one of four risk tiers and attaches duties to the role you play — provider, deployer, importer or distributor. Prohibitions, AI literacy, GPAI rules and Article 50 transparency already apply; the high-risk obligations apply from 02.12.2027.

Last reviewed · against the consolidated text and Commission guidance

113
articles, plus 13 annexes
4
risk tiers: prohibited, high, limited, minimal
02.08.2026
Article 50 transparency — in force
02.12.2027
high-risk (Annex III) obligations apply
The regulation

What is the EU AI Act?

Regulation (EU) 2024/1689 — the EU AI Act — is a product-safety style law for AI. It does not regulate “AI” as a technology; it regulates AI systems by the harm they can do, and it does that through a risk tier. A system is either prohibited (Art. 5), high-risk (Art. 6 with Annex I and Annex III), subject to transparency duties (Art. 50), or minimal-risk with no tier-specific duties at all. General-purpose AI models — the foundation models — have their own chapter (Art. 51–56).

It entered into force on 01.08.2024 and applies in stages, so “is it in force?” has a different answer for each chapter. The Digital Omnibus — Regulation (EU) 2026/1744, in force since 27.07.2026 — moved the high-risk dates and added two prohibitions; it did not move Article 50.

Scope

Who does the EU AI Act apply to?

Four operator roles, defined in Article 3. Your role — not your industry — decides which articles you owe. Like the GDPR, the Act reaches organisations outside the EU whenever a system's output is used in the Union.

Art. 3(3)

Provider

Develops an AI system or GPAI model, or has one developed, and places it on the market or puts it into service under its own name or trademark — paid or free.

Owes: The most: the Article 8–15 requirements for high-risk systems, conformity assessment, CE marking, registration, post-market monitoring, and Article 50(1)–(2) transparency.

Art. 3(4)

Deployer

Uses an AI system under its own authority in a professional context — the HR team running a screening tool, the bank running a credit model, the clinic running triage software.

Owes: Article 26: use the system as instructed, assign human oversight, keep logs, inform workers and affected people, run a FRIA where Article 27 applies, and disclose deepfakes under Article 50(4).

Art. 3(6)

Importer

Established in the EU and places on the market a system bearing the name of a provider established outside the EU.

Owes: Article 23: verify that the provider ran the conformity assessment, drew up the documentation and appointed an authorised representative before the system is placed on the market.

Art. 3(7)

Distributor

Makes a system available on the EU market without being its provider or importer — resellers, marketplaces, integrators who do not rebrand.

Owes: Article 24: check the CE marking, the declaration of conformity and the instructions for use, and withhold a system that does not conform.

Not sure which you are? Provider or deployer walks the Article 25 triggers that turn one into the other, and the free check asks the role question first.

Timeline

When does the EU AI Act apply? The key dates

The Act applies chapter by chapter. Four milestones are behind us; the high-risk wall is ahead. Every date below is read from the regulatory registry that runs the product, not typed into this page.

DateWhat appliesArticles
01.08.2024In forceThe Act enters into forceRegulation (EU) 2024/1689 was published in the Official Journal and became binding law. Nothing applied yet — the dates below are when each chapter started to bite.Art. 113
02.02.2025In forceProhibited practices and AI literacy applyThe Article 5 bans — social scoring, emotion recognition at work and in education, untargeted facial scraping and the rest — and the Article 4 duty to make staff AI-literate. These reach every provider and deployer, whatever the risk tier.Art. 5Art. 4
02.08.2025In forceGPAI obligations, governance and penalties applyProviders of general-purpose AI models owe documentation, copyright and training-data transparency duties; models with systemic risk owe more. The penalty regime and the national authorities came online the same day.Art. 53Art. 55Art. 99
02.08.2026In forceArticle 50 transparency duties applyChatbots must say they are AI, generated content must be marked, deepfakes must be disclosed. This date was not moved by the Digital Omnibus.Art. 50
02.12.2026AheadTwo new Article 5 prohibitions applyRegulation (EU) 2026/1744 adds bans on AI nudification tools and on AI-generated child sexual abuse material.Art. 5
02.12.2027AheadHigh-risk (Annex III) obligations applyThe bulk of the Act: risk management, data governance, technical documentation, human oversight, conformity assessment, CE marking, registration and the deployer duties. Deferred from 02.08.2026 by Regulation (EU) 2026/1744, in force since 27.07.2026.Art. 6Art. 8–15Art. 26
02.08.2028AheadAI in Annex I regulated products appliesHigh-risk AI that is a safety component of a product already covered by EU product law — machinery, medical devices, vehicles, toys. Deferred from 02.08.2027.Art. 6(1)

Systems already on the market before the high-risk date are covered by the transitional rules in Art. 111; the free tracker carries the original and Omnibus dates side by side.

Classification

What counts as high-risk AI?

Two routes into the tier, one filter out of it. Annex III names eight areas of use; Article 6(1) adds AI that is a safety component of a product already regulated under Annex I; Article 6(3) lets a provider document that an Annex III system does not pose a significant risk — unless it profiles people.

Annex III — the eight areas

  1. 1Biometrics
  2. 2Critical infrastructure
  3. 3Education and vocational training
  4. 4Employment, workers management and access to self-employment
  5. 5Access to essential private and public services and benefitsEligibility for essential public assistance benefits and services, including healthcare · Creditworthiness / credit scoring (excluding fraud detection) · Risk assessment and pricing in life and health insurance · Emergency call classification and dispatch, including emergency healthcare patient triage
  6. 6Law enforcement
  7. 7Migration, asylum and border control
  8. 8Administration of justice and democratic processes
Art. 6(1)

Annex I — AI inside regulated products

AI that is a safety component of a product covered by the EU product laws listed in Annex I — machinery, medical devices, in-vitro diagnostics, lifts, toys, vehicles, aviation — and that must go through third-party conformity assessment under that law.
Art. 6(3)

The filter: no significant risk

An Annex III system is not high-risk if it only performs a narrow procedural task, improves a completed human activity, detects decision patterns without replacing the assessment, or does preparatory work. The provider documents that assessment before placing the system on the market. Profiling of natural persons overrides the filter.
Art. 8–15

What high-risk means in practice

Risk management, data governance, Annex IV technical documentation, logging, instructions for deployers, human oversight, accuracy and cybersecurity — then conformity assessment, CE marking and registration before the system is placed on the market.

Deeper: the Annex III areas and the Article 6(3) exception in the help centre.

Three questions

What is your AI system's risk tier?

A first orientation in under a minute. Answer for one system at a time; the result names the tier and the articles that follow from it.

  1. Question 1
    Art. 5
    Does the system do anything Article 5 prohibits?

    Social scoring, untargeted facial-image scraping, emotion recognition at work or in education, real-time remote biometric identification in public spaces for law enforcement (outside the narrow exceptions), and — from the Digital Omnibus — AI nudification and AI-generated child sexual abuse material.

Obligations by role

Provider vs deployer: who owes what

The same high-risk system produces two different obligation lists depending on which side of it you sit. In the rules Veritome ships, a deployer of one high-risk system carries 12 obligations and a provider carries 23, out of 69 EU AI Act requirements the engine models.

ObligationProviderDeployerImporterDistributor
Art. 9Risk management system
Art. 10Data and data governance
Art. 11Technical documentation (Annex IV)
Art. 12Record-keeping and automatic logging
Art. 13Transparency and instructions for deployers
Art. 14Human oversight
Art. 15Accuracy, robustness and cybersecurity
Art. 17Quality management system
Art. 23–24Verify the provider's conformity before supply
Art. 26Deployer duties: use as instructed, oversight, logs, worker notice
Art. 27Fundamental rights impact assessment (FRIA)
Art. 43Conformity assessment and CE marking
Art. 49Registration in the EU database
Art. 50Transparency to people (chatbots, generated content, deepfakes)
Art. 72–73Post-market monitoring and serious-incident reporting

Importers and distributors owe the verification duties in Art. 23 and Art. 24, and any of the four becomes the provider under Art. 25 by rebranding a high-risk system, changing its intended purpose, or substantially modifying it.

Transparency

Article 50: the duties that reach almost everyone

Article 50 applies on top of the risk tier, based on how the AI touches people. It has been in force since 02.08.2026 and was not deferred by the Digital Omnibus.

Art. 50(1)

Tell people they are talking to AI

Chatbots and voice assistants must make the AI interaction clear unless it is obvious from the context.
Art. 50(2)

Mark generated content

Providers of generative systems mark synthetic audio, image, video and text in a machine-readable, detectable way.
Art. 50(3)

Disclose emotion recognition

Deployers of emotion-recognition or biometric-categorisation systems tell the people exposed to them.
Art. 50(4)

Disclose deepfakes

Deployers disclose deepfakes and AI-written text published on matters of public interest, unless a human takes editorial responsibility.
Enforcement

What are the penalties?

Article 99 sets three bands. The higher of the amount or the percentage applies; for SMEs and start-ups, the lower. National market-surveillance authorities enforce the Act for AI systems; the Commission's AI Office enforces it for general-purpose AI models.

InfringementMaximum fine
Prohibited practices (Art. 5)€35m or 7% of worldwide annual turnover
Most other obligations (e.g. high-risk duties)€15m or 3% of worldwide annual turnover
Incorrect/incomplete/misleading info to authorities€7.5m or 1% of worldwide annual turnover

The fine is the ceiling, not the tariff: authorities weigh the nature and duration of the breach, whether it was intentional, and what the operator did about it (Art. 99(7)). Details in penalties and enforcement.

The path

How to comply with the EU AI Act: six phases

The order the work has to happen in — the same six gated phases the product runs. You cannot register what you have not assessed, or assess what you have not classified.

  1. 01ClassifyWork through role, risk and prohibited-use — to review and confirm
  2. 02Scope & literacyApplicable obligations derived + Art. 4 AI literacy
  3. 03Build & documentRisk management, data governance, oversight & tech docs
  4. 04Conformity assessmentConformity assessment, declaration and CE marking
  5. 05RegisterEU database registration before market placement
  6. 06Operate & monitorPost-market monitoring, incident reporting, retention
Alongside

The EU AI Act and the GDPR

The two regimes apply at the same time. A high-risk system that processes personal data owes both an Annex IV technical file and, usually, a DPIA — and the Act itself sends deployers to the GDPR in Article 26(9).

Where they overlap the work is shared, not doubled: the Article 27 fundamental rights impact assessment and the GDPR Article 35 DPIA answer overlapping questions, the Article 13 information a provider hands over feeds the deployer's DPIA, and Article 22 (solely automated decisions) sits next to the Article 26(11) duty to inform affected people. How Veritome models the five frameworks as one register shows which records count twice.

Straight answers

EU AI Act: frequently asked questions

What is the EU AI Act?

The EU AI Act is Regulation (EU) 2024/1689, the European Union's law on artificial intelligence. It sorts AI systems into four risk tiers — prohibited, high-risk, limited-risk and minimal-risk — and attaches obligations to each tier and to each operator role: provider, deployer, importer and distributor. It has 113 articles and 13 annexes and has been in force since 01.08.2024.

Who does the EU AI Act apply to?

Anyone who places an AI system on the EU market or uses one in the EU in a professional capacity: providers (who build or brand it), deployers (who use it), importers and distributors. Like the GDPR it reaches organisations outside the EU whenever the system's output is used in the Union. Purely personal, non-professional use is out of scope.

What is the difference between a provider and a deployer?

A provider develops the system, or has it developed, and places it on the market under its own name. A deployer uses it under its own authority. The distinction decides your obligations: providers carry Articles 8–15 and the conformity route; deployers carry Article 26. A deployer that puts its own name on a high-risk system, changes its intended purpose or substantially modifies it becomes the provider under Article 25.

When does the EU AI Act apply?

In stages. Prohibited practices and AI-literacy duties have applied since 02.02.2025; GPAI model obligations and the penalty regime since 02.08.2025; Article 50 transparency since 02.08.2026. Two new Article 5 prohibitions apply from 02.12.2026. High-risk (Annex III) obligations apply from 02.12.2027 and AI in Annex I regulated products from 02.08.2028 — both deferred by Regulation (EU) 2026/1744, the Digital Omnibus, in force since 27.07.2026.

What counts as a high-risk AI system?

Two routes. Annex III lists eight areas — biometrics, critical infrastructure, education, employment, essential services such as credit and insurance, law enforcement, migration and border control, justice and democratic processes. Article 6(1) adds AI that is a safety component of a product covered by the Annex I product laws, such as medical devices or machinery. Article 6(3) lets a provider document that an Annex III system does not pose a significant risk — unless it profiles natural persons, in which case it is high-risk regardless.

What are the penalties for non-compliance?

Prohibited practices (Art. 5): up to €35m or 7% of worldwide annual turnover, whichever is higher. Most other obligations (e.g. high-risk duties): up to €15m or 3% of worldwide annual turnover, whichever is higher. Incorrect/incomplete/misleading info to authorities: up to €7.5m or 1% of worldwide annual turnover, whichever is higher. For SMEs and start-ups the lower of the two figures applies (Art. 99(6)).

Does the EU AI Act apply to AI tools we use but did not build?

Yes — as a deployer. Using a third-party recruitment screener, credit model or chatbot in a professional context brings Article 26: use it according to the provider's instructions, assign human oversight, keep the logs, tell workers and affected people, and, for public bodies and certain private deployers, run a fundamental rights impact assessment under Article 27 before first use.

Are SMEs exempt from the EU AI Act?

No. The obligations apply regardless of size. What SMEs get is proportionality: fines capped at the lower of the amount or percentage (Art. 99(6)), priority access to regulatory sandboxes (Art. 62), simplified technical-documentation forms for microenterprises, and lighter quality-management expectations. The classification and the core high-risk duties are the same.