Skip to content
Amended. Regulation (EU) 2026/1744 entered into force 27 July 2026. See what moved →
EU AI Act ChecklistIndependent reference
Regulation (EU) 2024/1689, as amended

The EU AI Act, complete and current

This is the whole Regulation in one page: what it covers, who it binds, what each tier owes, and when. It reflects the consolidated text — Regulation (EU) 2024/1689 as amended by Regulation (EU) 2026/1744, in force since 27 July 2026. Where a summary you have read says the Annex III deadline is August 2026, it predates that amendment.

Reg. (EU) 2024/1689as amended by Reg. (EU) 2026/1744in force 27 Jul 2026

Start with three questions

Everything downstream depends on these, in this order. Skipping one is how compliance programmes end up building the wrong thing.

  1. Is it an AI system? Article 3(1) turns on inference, whether the system derives how to generate outputs from input, rather than executing rules a person wrote out. The definition, tested →
  2. Are you in scope, and in which role? Six categories of person, two extra-territorial hooks, six narrow exclusions, and Article 25, which turns deployers into providers. Scope → · Roles →
  3. Which tier is the system in? This decides your obligations and your date. Risk classification →

Where this usually goes next

Three situations account for most people reading this page. Each has a different answer.

A deal is blocked on an AI questionnaire

Legal will not sign until you can evidence how AI is governed. HumanAudit’s AI Trust Package is a fixed $3,500 over five business days: a public trust page, a pre-filled SIG Lite / CAIQ / SSPA Section K questionnaire bank, and your AI inventory and classification.

How this works for AI companies →

You need ISO/IEC 42001 documentation

23 clause-mapped AIMS documents with all 38 Annex A controls pre-populated, editable and yours to keep, from $199. Or score your gaps first: 18 questions, free, no signup to begin.

Free gap assessment →
See the three tiers →

You are not sure what reaches you

Twenty minutes with the founder. No prep, no deck, straight to the person accountable for the work. If none of this applies to you, you get told that on the call.

Book a free 20-minute call →

This reference is published by HumanAudit Inc. Not a law firm, not an accredited certification body, not a registered auditor. We build documentation, your counsel interprets it, and an accredited body of your choosing certifies you. How this is funded →

The four tiers

TierWhat it coversCore obligationMax fineApplies
UnacceptableArticle 5 prohibited practices, social scoring, untargeted facial-image scraping, most real-time remote biometric ID in public, emotion recognition at work and in education, and othersComplete prohibition€35M / 7%2 Feb 2025
two new prohibitions 2 Dec 2026
High riskAnnex III stand-alone systems (8 domains) and Annex I embedded safety componentsChapter III Section 2, risk management, data governance, technical documentation, logging, transparency to deployers, human oversight, accuracy and security, QMS, conformity assessment, registration, post-market monitoring€15M / 3%2 Dec 2027
Annex I: 2 Aug 2028
TransparencySystems that interact with people, generate synthetic content, recognise emotion, or produce deep fakes — at any risk tierArticle 50 disclosure€15M / 3%2 Aug 2026
MinimalEverything elseNo mandatory requirements under the Act, except Article 4 AI literacy, which applies at every tierArt. 4 since 2 Feb 2025

The tiers are not mutually exclusive

A high-risk recruitment tool that also talks to candidates owes Chapter III and Article 50. Reading the tiers as a single-choice classification is the most common structural error, and it produces compliance plans with a hole in them.

General-purpose AI models sit outside this table. Chapter V (Articles 51–56) applies to model providers on its own terms, has applied since 2 August 2025, and was not changed in substance by the Omnibus. GPAI obligations →

Every application date

  1. 2 Feb 2025 applies

    Article 5 prohibited practices (original list). Article 4 AI literacy.

  2. 2 Aug 2025 applies

    General-purpose AI model obligations, Chapter V (Arts. 51–55).

  3. 2 Aug 2026 applies

    Article 50 transparency. Article 49 registration. National market surveillance authority powers. General application date.

  4. 2 Dec 2026 next

    Two new Article 5 prohibitions (NCII/NCIM and CSAM generation). Article 50(2) machine-readable marking for generative systems already on the market before 2 Aug 2026.

  5. 2 Aug 2027 upcoming

    National regulatory sandboxes (deferred by Reg. 2026/1744).

  6. 2 Dec 2027 upcoming

    Annex III stand-alone high-risk obligations — Chapter III Sections 1, 2 and 3.

  7. 2 Aug 2028 upcoming

    Annex I embedded high-risk obligations (AI in regulated products).

  8. 2 Aug 2030 upcoming

    Article 111 transition ends for AI systems already in use by public authorities.

What the Omnibus deferred, precisely

The deferral concerns Chapter III Sections 1, 2 and 3: classification, requirements and provider obligations for high-risk systems. It did not defer the Article 5 prohibitions, Chapter V general-purpose AI, Article 50 transparency, Article 49 registration, or the general application date of 2 August 2026.

Expert analysis: commentary frequently collapses “the AI Act was delayed” with “the high-risk chapter was deferred”. They are not the same statement and the difference is roughly the whole of your live obligation set.

Reg. (EU) 2026/1744OJ L, 24 Jul 2026in force 27 Jul 2026

Timeline in detail → · What the Omnibus changed →

The high-risk obligations, article by article

These apply from 2 December 2027 for stand-alone Annex III systems. Each links to a full guide.

ArticleObligationThe part most often missed
Art. 9Risk management systemRisk to people, not to the organisation. Information to deployers is the last resort in the hierarchy of measures.
Art. 10Data and data governanceThe original purpose for which personal data was collected must be documented.
Art. 11Technical documentation (Annex IV)Nine prescribed headings, kept up to date, retained ten years.
Arts. 12–13Logging; instructions for useSix-month retention falls on provider and deployer, each for logs under their control.
Art. 14Human oversightFive specific capabilities, including the authority to override.
Art. 15Accuracy, robustness, cybersecurityFive AI-specific attack classes named in the Regulation itself.
Art. 17Quality management systemThirteen enumerated elements. ISO/IEC 42001 does not satisfy it.
Arts. 43–48Conformity assessment, declaration, CE markingInternal control for most Annex III. Not automatable.
Art. 49EU database registrationApplies even if you claim the Article 6(3) derogation.
Art. 72Post-market monitoringThe plan sits inside the Annex IV file and is examined before launch.
Art. 73Serious incident reporting15 days, 10 days for death, 2 days for widespread infringement.

Deployers owe a separate, shorter set under Article 26, plus Article 27 fundamental rights impact assessments for public bodies and certain essential-service deployers. The full split →

Penalties

InfringementMaximumBasis
Article 5 prohibited practices€35M or 7%Art. 99(3)
Other operator / notified body obligations, includes high-risk requirements and Article 50€15M or 3%Art. 99(4)
Incorrect, incomplete or misleading information to authorities€7.5M or 1%Art. 99(5)
GPAI model provider obligations (Commission-enforced)€15M or 3%Art. 101

Whichever is higher, except for SMEs and start-ups, where the lower applies. Penalties in detail, with calculator →

Where to start, honestly

Practical recommendation. The hard part of AI Act compliance is not the documentation template. It is finding every AI system in the organisation, deciding what each one is, and keeping that current as new systems ship. That work does not get easier by waiting for standards, and it gates everything else.

  1. Inventory. Every system, every surface. Record intended purpose, role, tier and owner.
  2. Fix what is live. Article 50 disclosure and Article 4 literacy are in force now and carry penalties.
  3. Classify. Annex III exposure, and whether Article 6(3) genuinely applies. The derogation →
  4. Build the file. For anything high-risk, Annex IV and the Article 9 risk file are the long lead items.

Status labels on this page

Verified fact: The tiers, dates, article obligations and penalty tiers set out above, checked against the consolidated Regulation and the Commission's AI Act Service Desk.

Expert analysis: The ordering advice, the observation about tiers not being mutually exclusive, and the 'inventory first' recommendation.

Unsettled: Harmonised standards remain in development, which affects how several Chapter III requirements will be evidenced in practice.

Where this usually goes next

From understanding to evidence

Every obligation above resolves to an artefact someone can inspect. The organisations that find this manageable are the ones that built a system to produce those artefacts rather than a project to write them once.

Not sure where you sit?

The classifier maps your system against Articles 5, 6, 50 and Annex III. Twelve questions, no email.

Run the classifier →

Frequently asked

What is the EU AI Act?

The EU AI Act is Regulation (EU) 2024/1689, the European Union's horizontal law on artificial intelligence. It was published in the Official Journal on 12 July 2024 and entered into force on 1 August 2024.

It classifies AI systems by risk and attaches proportionate obligations: prohibited practices under Article 5, high-risk systems under Article 6 and Annexes I and III, transparency obligations under Article 50, and a separate regime for general-purpose AI models in Chapter V. It was amended by Regulation (EU) 2026/1744, the Digital Omnibus on AI, which was published in the Official Journal on 24 July 2026 and entered into force on 27 July 2026.

Is the EU AI Act in force?

Yes. It entered into force on 1 August 2024 and applies in phases. Article 5 prohibitions and Article 4 AI literacy have applied since 2 February 2025. General-purpose AI model obligations have applied since 2 August 2025. Article 50 transparency, Article 49 registration and national market surveillance authority powers have applied since 2 August 2026. Obligations for stand-alone Annex III high-risk systems apply from 2 December 2027 and for Annex I embedded high-risk systems from 2 August 2028.

What are the four risk tiers of the EU AI Act?

Unacceptable risk, covered by the Article 5 prohibitions; high risk, covered by Article 6 with Annexes I and III and the requirements in Chapter III Section 2; limited or transparency risk, covered by the Article 50 disclosure duties; and minimal risk, which carries no mandatory requirements under the Act other than the Article 4 AI literacy duty which applies at every tier. General-purpose AI models sit alongside this structure in Chapter V rather than inside it.

What are the penalties under the EU AI Act?

Article 99 sets tiered maxima. Breach of the Article 5 prohibitions: up to 35 million euro or 7 percent of total worldwide annual turnover, whichever is higher. Breach of other operator or notified body obligations, which includes the high-risk requirements and Article 50 transparency: up to 15 million euro or 3 percent. Supplying incorrect, incomplete or misleading information to authorities: up to 7.5 million euro or 1 percent. Article 101 covers general-purpose AI model providers at up to 15 million euro or 3 percent, enforced by the Commission.

Does the EU AI Act apply to companies outside the EU?

Yes. Article 2 applies the Regulation to providers placing AI systems on the EU market or putting them into service in the EU irrespective of where they are established, and to providers and deployers in third countries where the output produced by the AI system is used in the EU. Regulation (EU) 2026/1744 did not narrow this territorial scope.

Guides by role and by sector

The obligations are the same; what lands on your desk is not. These take the same Regulation from a specific starting point.

By role. Board & executive · General counsel · CISO · DPO · CTO · Product manager · Internal audit · Consultants & advisers

By sector. HR & recruitment · Financial services · Insurance · MedTech · Manufacturing · Automotive · B2B SaaS · Law firms · Public sector · Startups & SMEs

Proving it to a buyer. AI governance in procurement · Microsoft SSPA Section K · AI system inventory · Vendor due diligence · Supplier programme · Third-party AI risk · Contract clauses · Maturity self-assessment · AI risk library

Edge cases and scope questions. Open-source exemptions · Regulatory sandboxes (Art. 57) · Global AI regulation · Territorial scope

How this site works. About & funding · Editorial standards · Glossary · Article index