VeritomeHelp Centre
/
Browse documentation
EU AI Act in depth

Glossary and FAQ

A quick reference for the EU AI Act terms, dates and articles that come up most often, plus answers to the questions people ask first.

Updated Veritome documentation

A quick reference for the terms, dates and articles that come up most often. For the narrative version, read the EU AI Act primer first.

Enforcement timeline

The EU AI Act entered into force on 1 August 2024 and applies in stages under Art. 113, as revised by the Digital Omnibus (Regulation (EU) 2026/1744, in force since 27 July 2026):

DateWhat applies
1 Aug 2024The Act enters into force. The clocks start; nothing is enforceable yet.
2 Feb 2025Prohibited practices (Art. 5) and AI literacy (Art. 4) — in force.
2 Aug 2025GPAI model obligations (Art. 53 / 55), the governance bodies, and the penalty regime (Art. 99; the Art. 101 fines for GPAI providers apply from 2 Aug 2026) — in force.
2 Aug 2026Art. 50 transparency duties — in force.
2 Dec 2026The two new Art. 5 prohibitions (Art. 5(1), points (ba) and (bb): AI nudification; AI-generated child sexual abuse material); synthetic-content systems on the market before 2 August 2026 must meet Art. 50(2) by this date (Art. 111(4)).
2 Aug 2027Deadline for GPAI models placed on the market before 2 Aug 2025 to conform.
2 Dec 2027Annex III high-risk systems (Art. 6(2)) — deferred from 2 Aug 2026 by Regulation (EU) 2026/1744 (Digital Omnibus).
2 Aug 2028High-risk safety components of regulated products — the Art. 6(1) product route — deferred from 2 Aug 2027 by Regulation (EU) 2026/1744.

If you are standing up compliance now, plan backwards from 2 December 2027 for Annex III high-risk systems. The Art. 50 transparency duties already apply.

Article quick-reference

Article / AnnexWhat it covers
Art. 3Definitions — provider 3(3), deployer 3(4), importer 3(6), distributor 3(7), substantial modification 3(23), serious incident 3(49), GPAI model 3(63).
Art. 4AI literacy — all providers and deployers.
Art. 5Prohibited practices, including the two added by the Digital Omnibus.
Art. 6High-risk classification — 6(1) product route, 6(2) Annex III, 6(3) the exception, 6(4) its documentation.
Art. 8–15The high-risk requirements — Art. 9 risk management, Art. 10 data governance, Art. 11 + Annex IV technical documentation, Art. 12 logging, Art. 13 instructions for use, Art. 14 human oversight, Art. 15 accuracy, robustness and cybersecurity.
Art. 16 / 17 / 18 / 19Provider obligations / quality management system / documentation kept 10 years / logs kept at least six months.
Art. 22 / 54Authorised representative — high-risk systems / GPAI models.
Art. 23 / 24Importer / distributor obligations.
Art. 25Role changes along the chain (own name / substantial modification / change of purpose); 25(4) written agreements with suppliers.
Art. 26Deployer obligations — 26(6) logs at least six months, 26(7) inform workers, 26(9) use the instructions in the DPIA, 26(11) inform affected persons.
Art. 27Fundamental-rights impact assessment (FRIA); 27(3) notify the authority, 27(4) complements a DPIA.
Art. 43 / 47 / 48Conformity assessment / Declaration of Conformity (Annex V, kept 10 years) / CE marking.
Art. 49 + Annex VIIIRegistration in the EU database; 49(2) for systems relying on the Art. 6(3) exception.
Art. 50Transparency obligations.
Art. 51–56GPAI models (Chapter V) — 53 all providers, 55 systemic risk.
Art. 72 / 73Post-market monitoring / serious-incident reporting (15 / 10 / 2 calendar days).
Art. 86Right to an explanation of individual decision-making.
Art. 99 / 101 / 113Penalties / GPAI fines / entry into force and phased dates.

Glossary

  • AI system (Art. 3(1)) — a machine-based system that infers, from its input, how to generate outputs (predictions, content, recommendations, decisions) that can influence physical or virtual environments.
  • GPAI model (Art. 3(63)) — a general-purpose AI model trained on broad data and usable across many tasks; regulated under Chapter V (Art. 51–56).
  • Authorised representative (Art. 22 / 54) — an EU-based entity a non-EU provider appoints by written mandate to act for it under the Act.
  • Substantial modification (Art. 3(23) / Art. 25) — a change to a system after it is on the market that is not foreseen in the provider's initial conformity assessment and affects its compliance or intended purpose; can make the modifier a provider.
  • Profiling — automated processing to evaluate personal aspects of a natural person (the GDPR's definition); under Art. 6(3) it makes an Annex III system always high-risk, overriding any exception.
  • Systemic risk (Art. 51) — the classification that pulls a GPAI model into the heavier Art. 55 obligations; presumed above 10²⁵ FLOP of training compute.
  • Annex I / III / IV / V / VIII / XI / XII — product-safety legislation (6(1) route) / the eight high-risk use areas / the contents of technical documentation / the declaration of conformity / the EU-database registration field set / GPAI model documentation / GPAI downstream information.
  • CE marking (Art. 48) / DoC (Art. 47, kept 10 years) / Conformity assessment (Art. 43, Annex VI internal control or Annex VII notified body) / Notified body / Harmonised standard (none yet cited for the Act).
  • FRIA (Art. 27) — fundamental-rights impact assessment, required of certain deployers of Annex III systems before first use.
  • IFU (Art. 13) — instructions for use a provider must give a deployer.
  • Post-market monitoring (Art. 72) / Serious incident (Art. 3(49) / Art. 73, reportable in 15 / 10 / 2 calendar days from awareness).
  • Market-surveillance authority — the national body that enforces the Act and receives incident notifications. AI Office — the Commission body overseeing GPAI models.
  • Digital Omnibus — Regulation (EU) 2026/1744, in force since 27 July 2026, which deferred the two high-risk dates and added two Art. 5 prohibitions.

FAQ

Does the Act apply to us if we only use AI, not build it? Yes. Deployers have real duties under Art. 26 — human oversight, keeping logs for at least six months, informing affected workers and affected persons — and, for some, a FRIA (Art. 27). AI literacy (Art. 4) applies to every deployer regardless of tier. See Deployer duties under Article 26.

We use a third-party model under our own brand. Are we a provider? Quite possibly. Placing a system on the market under your own name, or substantially modifying a high-risk one, upgrades you to provider under Art. 25.

We're based outside the EU — does the Act reach us? It can. Under Art. 2 it applies to providers placing systems on the EU market wherever established, to deployers in the Union, and where the system's output is used in the Union. A non-EU provider of a high-risk system must appoint an EU authorised representative (Art. 22).

What's the difference between prohibited and high-risk? A prohibited system (Art. 5) cannot be placed on the market or used at all. A high-risk system (Art. 6) is allowed once you meet the full requirement set, pass conformity assessment, and register it. Prohibited is a ban; high-risk is a licence with conditions.

Is "minimal risk" the same as "exempt"? There are no mandatory obligations for minimal-risk systems, but Art. 50 transparency can still apply if it is a chatbot or generates content, and Art. 4 literacy applies to every operator.

Do the GPAI obligations apply if we just call an API? No — the Chapter V duties sit with the model provider. You inherit the downstream information they must give you, and may still owe Art. 50 transparency on the system you build. Only if you train or release a GPAI model do Art. 53 (and, for systemic risk, Art. 55) fall on you.

Is a FRIA the same as a GDPR DPIA? No. A FRIA (Art. 27) assesses impacts on fundamental rights and is a deployer duty for certain Annex III systems; a DPIA (GDPR Art. 35) assesses data-protection risk. Art. 27(4) says the FRIA complements a DPIA already done, so they reference each other — but one does not discharge the other. See DPIA overlap.

Do we have to register every AI system in the EU database? No — Art. 49 registration is for high-risk systems (providers, and public-authority deployers), and for systems a provider has concluded are not high-risk under Art. 6(3). Keeping your own internal inventory, though, is expected of everyone.

Does an ISO/IEC 42001 certificate mean we comply with the Act? No. No harmonised standard has been cited in the Official Journal, so no certificate gives a presumption of conformity. See ISO/IEC 42001 explained.

Does Aria's classification count as our decision? No. Aria proposes; a human confirms. The confirmed decision — with who confirmed it — is what lands in your audit trail.