AI Act explorer Every article that matters. One-line summaries.
Skim the articles relevant to your situation. Filter by chapter. For a tailored obligation list, take the 2-minute scoping.
I. General provisions
-
▸ 1 Subject matter
Applies to: AllApplicable from:2025-02-02 Sets the AI Act's purpose: harmonised rules for AI placed on the EU market, ensuring high level of protection of health, safety, fundamental rights.
-
▸ 2 Scope
Applies to: All — including non-EU providers/deployersApplicable from:2025-02-02 Extraterritorial reach: applies where the AI output is used in the EU, regardless of establishment location. Article 2(1)(c) is the US-targeting wedge.
-
▸ 3 Definitions
Applies to: AllApplicable from:2025-02-02 Defines AI system, provider, deployer, importer, distributor, operator, GPAI model, biometric data, risk, etc. Critical for any compliance argument.
-
▸ 4 AI literacy
Applies to: Providers + deployersApplicable from:2025-02-02 Must ensure sufficient AI literacy of staff dealing with AI systems. Operative since 2 Feb 2025.
II. Prohibited practices
-
▸ 5 Prohibited AI practices
Applies to: AllApplicable from:2025-02-02 Bans social scoring by public/private actors, exploitation of vulnerabilities, untargeted scraping for face databases, emotion recognition in workplaces/schools (with exceptions), biometric categorisation by sensitive attributes, real-time remote biometric ID in public spaces (narrow law-enforcement exceptions), predictive policing of natural persons.
III. High-risk AI
-
▸ 6 Classification rules for high-risk
Applies to: ProvidersApplicable from:2027-12-02 Defines what makes a system high-risk: covered by Annex I safety legislation, OR listed in Annex III use cases. Determination is the gateway for the entire Chapter III obligation chain.
-
▸ 9 Risk management system
Applies to: Providers of high-risk AIApplicable from:2027-12-02 Continuous, iterative risk-management process across the lifecycle. Identification, estimation, evaluation, mitigation of known and reasonably foreseeable risks. Documented in technical documentation.
-
▸ 10 Data and data governance
Applies to: Providers of high-risk AIApplicable from:2027-12-02 Training/validation/testing data must meet quality criteria: relevant, representative, free of errors, complete. Special-category data permitted only for bias mitigation. Documentation of data sources required.
-
▸ 11 Technical documentation
Applies to: Providers of high-risk AIApplicable from:2027-12-02 Annex IV-prescribed dossier covering system description, design choices, training data, performance metrics, risk management, post-market plan. Must exist BEFORE placing on market. Single most underestimated artefact.
-
▸ 12 Record-keeping
Applies to: Providers of high-risk AIApplicable from:2027-12-02 Automatic logging of events over the system's lifetime, enabling traceability. Logs retained by deployer (Art. 26(6)).
-
▸ 13 Transparency + information to deployers
Applies to: Providers of high-risk AIApplicable from:2027-12-02 Instructions for use including system characteristics, accuracy, robustness, foreseeable misuse, hardware/software needs, human-oversight measures.
-
▸ 14 Human oversight
Applies to: Providers + deployers of high-risk AIApplicable from:2027-12-02 System must be designed to be effectively overseen by natural persons. 'Stop' button, ability to override, interpretability tools.
-
▸ 15 Accuracy, robustness and cybersecurity
Applies to: Providers of high-risk AIApplicable from:2027-12-02 Appropriate accuracy levels declared in instructions for use. Resilience to errors and inconsistencies. Resilience to adversarial attacks (data poisoning, model evasion). State of the art at the time of placing on market.
-
▸ 16-22 Obligations of providers
Applies to: Providers of high-risk AIApplicable from:2027-12-02 Compliance with Chapter III, quality-management system (Art. 17), documentation retention 10 years (Art. 18), logging retention (Art. 19), corrective actions (Art. 20), cooperation with authorities (Art. 21), authorised representatives in EU for non-EU providers (Art. 22).
-
▸ 26 Obligations of deployers
Applies to: Deployers of high-risk AIApplicable from:2027-12-02 Use per instructions; assign human oversight; ensure input data appropriateness; monitor operation; keep logs ≥6 months; inform workers + workers' reps for workplace use; FRIA (Fundamental Rights Impact Assessment) for public-sector + credit/insurance use.
-
▸ 27 FRIA
Applies to: Public-sector + credit/insurance deployersApplicable from:2027-12-02 Fundamental Rights Impact Assessment before first deployment. Categories of natural persons affected, intended purpose, risks, oversight measures, human review of outputs.
-
▸ 43 Conformity assessment
Applies to: Providers of high-risk AIApplicable from:2027-12-02 Internal control (Annex VI) or third-party with notified body (Annex VII) depending on category. CE marking after success. Re-assessment required on substantial modification.
-
▸ 47 EU Declaration of Conformity
Applies to: Providers of high-risk AIApplicable from:2027-12-02 Single declaration per system stating compliance with the Act. Retained 10 years; updated as needed.
-
▸ 49 Registration in EU database
Applies to: Providers + public-sector deployers of high-risk AIApplicable from:2027-12-02 Public EU database of high-risk AI systems. Annex VIII data (system name, intended purpose, provider/deployer details, CE marking).
IV. Transparency
-
▸ 50 Transparency obligations for certain AI systems
Applies to: Providers + deployersApplicable from:2026-08-02 Disclose AI when interacting with humans; biometric categorisation/emotion recognition systems must inform subjects; deepfake content must be labelled; AI-generated text on matters of public interest must be disclosed unless edited by human.
V. GPAI models
-
▸ 51 Classification rules for GPAI
Applies to: GPAI providersApplicable from:2025-08-02 GPAI = model with significant generality and capability across distinct tasks. Systemic-risk GPAI: above 10²⁵ FLOPs training compute OR designated by Commission.
-
▸ 53 Obligations for GPAI providers
Applies to: GPAI providersApplicable from:2025-08-02 Technical documentation (Annex XI), information for downstream providers (Annex XII), copyright-law-compliance policy, public summary of training content.
-
▸ 55 Obligations for systemic-risk GPAI
Applies to: Systemic-risk GPAI providersApplicable from:2025-08-02 Model evaluation per state-of-the-art protocols, adversarial testing, assessment + mitigation of EU-level systemic risks, serious-incident tracking and reporting to AI Office, cybersecurity protection.
VII. Governance
-
▸ 64-70 AI Office + AI Board + Advisory Forum
Applies to: AuthoritiesApplicable from:2025-08-02 Sets up the EU AI Office (Commission DG-CNECT), the AI Board (Member State reps), and the Advisory Forum. The Office leads on GPAI; national authorities lead on other categories.
IX. Post-market
-
▸ 72 Post-market monitoring plan
Applies to: Providers of high-risk AIApplicable from:2027-12-02 Documented plan, proportionate to risk. Active collection + analysis of relevant data from deployers throughout the lifetime of the system.
-
▸ 73 Serious incident reporting
Applies to: Providers of high-risk AIApplicable from:2027-12-02 Report to market surveillance authorities within 15 days of awareness (or 2 days for widespread infringement / serious irreversibility). Investigation cooperation required.
XII. Penalties
-
▸ 99 Penalties for providers + deployers
Applies to: AllApplicable from:2025-08-02 Prohibited practices (Art. 5): €35M / 7% of global annual turnover, whichever higher. Most other violations: €15M / 3%. Incorrect info to authorities: €7.5M / 1%. SMEs and startups: lower of the two.
-
▸ 101 Penalties for GPAI providers
Applies to: GPAI providersApplicable from:2025-08-02 Up to €15M / 3% of global annual turnover. AI Office enforcement.
Annexes
-
▸ Annex III High-risk use cases
Applies to: Providers + deployersApplicable from:2027-12-02 8 categories: biometrics, critical infrastructure, education, employment, essential services (credit, insurance, public welfare), law enforcement, migration, justice administration.
-
▸ Annex IV Technical documentation
Applies to: Providers of high-risk AIApplicable from:2027-12-02 Required structure: general description; design specifications; description of monitoring/control; risk management; pre-determined changes; standards applied; declaration of conformity; post-market plan. Single most labour-intensive deliverable.