EU AI Act primer: roles, risk tiers, GPAI and deadlines
A plain-language tour of the whole Act — who it binds, how it sorts systems by risk, what general-purpose AI adds, when each part applies after the Digital Omnibus, and what non-compliance costs.
A plain-language tour of the EU AI Act — Regulation (EU) 2024/1689, 113 articles and 13 annexes, as amended by the Digital Omnibus (Regulation (EU) 2026/1744). The Act is risk-based: the more an AI system can hurt people's health, safety or fundamental rights, the more you must do before and after you put it on the market. It regulates AI systems (and separately general-purpose AI models), and attaches duties to your role in the value chain — not just to the technology.
This is an explainer, not legal advice. Veritome structures the work and cites the articles; you and your advisers own the final call.
1 · The four operator roles
The same model can make you a provider in one deployment and a deployer in another, so the Act pins obligations to your position in the chain.
| Role | Definition | You are… | Core duties |
|---|---|---|---|
| Provider | Art. 3(3) | Developing an AI system (or having one built) and placing it on the market or putting it into service under your own name or trade mark. | The full high-risk set — Art. 16: the requirements (Art. 8–15), a quality management system (Art. 17), conformity assessment (Art. 43), DoC (Art. 47) + CE marking (Art. 48), registration (Art. 49), post-market monitoring (Art. 72). Heaviest. |
| Deployer | Art. 3(4) | Using an AI system under your own authority in a professional context. | Art. 26 — use per the instructions, human oversight, keep logs at least six months (Art. 26(6)), inform affected workers (Art. 26(7)); a FRIA (Art. 27) for some. |
| Importer | Art. 3(6) | Placing a non-EU provider's system on the EU market. | Art. 23 — verify the provider's conformity assessment, technical documentation, CE marking and EU authorised representative before placing it. |
| Distributor | Art. 3(7) | Making a system available without changing it. | Art. 24 — check the CE marking and documents are present, and act on any non-conformity you learn of. Lightest. |
Role can upgrade. Under Art. 25 an importer, distributor or deployer who puts a high-risk system on the market under their own name or trade mark, substantially modifies it, or changes its intended purpose so that it becomes high-risk, becomes its provider. A non-EU provider must appoint an EU authorised representative (Art. 22 for high-risk systems, Art. 54 for GPAI models). See Am I a provider or a deployer?
2 · The four risk tiers
| Tier | Test | What it means |
|---|---|---|
| Prohibited | Art. 5 | Banned outright — harmful manipulation, exploiting vulnerabilities, social scoring, predictive policing by profiling alone, untargeted facial-image scraping, emotion inference at work and in education, sensitive biometric categorisation, real-time remote biometric identification in public for law enforcement (narrow exceptions). Two further prohibitions added by Regulation (EU) 2026/1744 — AI "nudification" tools and AI-generated child sexual abuse material — apply from 2 Dec 2026. You cannot place any of them on the market or use them. |
| High-risk | Art. 6 | Either a safety component of a regulated product (Art. 6(1) + Annex I) or a use listed in Annex III (Art. 6(2)). Triggers the full requirement set (Art. 8–15) and the conformity route. |
| Transparency (limited) | Art. 50 | Interacts with people, generates synthetic content, recognises emotions or categorises by biometrics, or produces deep fakes. You must disclose — tell people they are dealing with AI, mark synthetic content, label deep fakes. |
| Minimal | — | Everything else (spam filters, game AI, inventory forecasting). No mandatory obligations; voluntary codes of conduct encouraged (Art. 95). |
The tiers layer: a minimal-risk chatbot still owes Art. 50 transparency, and a high-risk hiring tool that also generates content owes both its Annex III duties and the Art. 50 marking duties.
3 · High-risk, in a little more detail
There are two independent routes into high-risk (Art. 6): the product route (Art. 6(1) + Annex I — a safety component of a product that needs third-party conformity assessment under the listed product legislation) and the Annex III route (Art. 6(2) — one of eight listed high-risk areas). The Art. 6(3) exception is disjunctive: an Annex III system is not high-risk if it does not pose a significant risk of harm because it meets at least one of four conditions — but profiling of natural persons is always high-risk and overrides any exception, and a provider relying on the exception must document the assessment (Art. 6(4)). See The Annex III high-risk areas and The Article 6(3) exception.
4 · General-purpose AI (GPAI) models
A GPAI model (Art. 3(63)) is regulated as a model under Chapter V (Art. 51–56), separately from the systems built on it: Art. 53 duties for all GPAI providers (technical documentation, downstream information, copyright policy, training-content summary); Art. 55 additional duties where the model carries systemic risk (Art. 51); Art. 54 for non-EU providers; Art. 56 codes of practice. If you only call a third-party GPAI API, those duties sit with the model provider. See What counts as GPAI.
5 · Key duties, by article
- Art. 9 — risk-management system (continuous, iterative). Art. 10 — data & data governance. Art. 11 + Annex IV — technical documentation. Art. 12 — logging. Art. 13 — instructions for use to deployers. Art. 14 — human oversight. Art. 15 — accuracy, robustness and cybersecurity. Art. 17 — quality management system. Art. 18 — keep the documentation for 10 years.
- Art. 26 — deployer duties; Art. 27 — FRIA (a deployer duty). Art. 43 — conformity assessment; Art. 47 + Annex V — Declaration of Conformity (kept 10 years); Art. 48 — CE marking; Art. 49 + Annex VIII — EU-database registration.
- Art. 72 — post-market monitoring; Art. 73 — serious-incident reporting (15 days in general, 10 where a death may have been caused, 2 for a widespread infringement or critical-infrastructure disruption — calendar days from awareness).
See High-risk provider requirements and Deployer duties under Article 26 for the two stacks in order.
6 · When it applies — the deadlines
The Act entered into force on 1 August 2024 and applies in stages under Art. 113, as revised by the Digital Omnibus:
| Date | What starts to apply |
|---|---|
| 2 Feb 2025 | Prohibited practices (Art. 5) and AI literacy (Art. 4). In force. |
| 2 Aug 2025 | GPAI model obligations (Art. 53 / 55), the governance bodies (AI Office / Board), and the penalty regime (Art. 99; the Art. 101 fines for GPAI providers apply from 2 Aug 2026). In force. |
| 2 Aug 2026 | Art. 50 transparency duties. In force. |
| 2 Dec 2026 | The two new Art. 5 prohibitions — Art. 5(1), points (ba) and (bb): AI nudification; AI-generated child sexual abuse material — added by Regulation (EU) 2026/1744. Also the date by which synthetic-content systems already on the market before 2 August 2026 must meet Art. 50(2) (Art. 111(4)). |
| 2 Aug 2027 | Deadline for GPAI models already on the market before 2 Aug 2025 to conform. |
| 2 Dec 2027 | Annex III high-risk systems (Art. 6(2)) — deferred from 2 Aug 2026 by the Digital Omnibus, Regulation (EU) 2026/1744, in force since 27 July 2026. The milestone most organisations plan back from. |
| 2 Aug 2028 | High-risk safety components of regulated products — the Art. 6(1) product route — deferred from 2 Aug 2027 by Regulation (EU) 2026/1744. |
7 · Penalties — Article 99
Fines are the higher of a fixed amount or a percentage of worldwide annual turnover: €35M / 7% for breaching the Art. 5 prohibitions; €15M / 3% for most other operator obligations; €7.5M / 1% for incorrect, incomplete or misleading information to authorities. For SMEs and start-ups the fine is the lower of the two (Art. 99(6)); since the Digital Omnibus, small mid-caps (SMCs) get the same lower-of rule for the Art. 99(4) and (5) tiers. See Penalties: what non-compliance actually costs.
Always confirm dates against the regulatory registry inside the app — it is kept current and every date on screen is read from it. For the quick lookup version of the terms and articles, see Glossary and FAQ.