The EU AI Act, complete and current
This is the whole Regulation in one page: what it covers, who it binds, what each tier owes, and when. It reflects the consolidated text — Regulation (EU) 2024/1689 as amended by Regulation (EU) 2026/1744, in force since 27 July 2026. Where a summary you have read says the Annex III deadline is August 2026, it predates that amendment.
Start with three questions
Everything downstream depends on these, in this order. Skipping one is how compliance programmes end up building the wrong thing.
- Is it an AI system? Article 3(1) turns on inference, whether the system derives how to generate outputs from input, rather than executing rules a person wrote out. The definition, tested →
- Are you in scope, and in which role? Six categories of person, two extra-territorial hooks, six narrow exclusions, and Article 25, which turns deployers into providers. Scope → · Roles →
- Which tier is the system in? This decides your obligations and your date. Risk classification →
Where this usually goes next
Three situations account for most people reading this page. Each has a different answer.
A deal is blocked on an AI questionnaire
Legal will not sign until you can evidence how AI is governed. HumanAudit’s AI Trust Package is a fixed $3,500 over five business days: a public trust page, a pre-filled SIG Lite / CAIQ / SSPA Section K questionnaire bank, and your AI inventory and classification.
You need ISO/IEC 42001 documentation
23 clause-mapped AIMS documents with all 38 Annex A controls pre-populated, editable and yours to keep, from $199. Or score your gaps first: 18 questions, free, no signup to begin.
You are not sure what reaches you
Twenty minutes with the founder. No prep, no deck, straight to the person accountable for the work. If none of this applies to you, you get told that on the call.
This reference is published by HumanAudit Inc. Not a law firm, not an accredited certification body, not a registered auditor. We build documentation, your counsel interprets it, and an accredited body of your choosing certifies you. How this is funded →
The four tiers
| Tier | What it covers | Core obligation | Max fine | Applies |
|---|---|---|---|---|
| Unacceptable | Article 5 prohibited practices, social scoring, untargeted facial-image scraping, most real-time remote biometric ID in public, emotion recognition at work and in education, and others | Complete prohibition | €35M / 7% | 2 Feb 2025 two new prohibitions 2 Dec 2026 |
| High risk | Annex III stand-alone systems (8 domains) and Annex I embedded safety components | Chapter III Section 2, risk management, data governance, technical documentation, logging, transparency to deployers, human oversight, accuracy and security, QMS, conformity assessment, registration, post-market monitoring | €15M / 3% | 2 Dec 2027 Annex I: 2 Aug 2028 |
| Transparency | Systems that interact with people, generate synthetic content, recognise emotion, or produce deep fakes — at any risk tier | Article 50 disclosure | €15M / 3% | 2 Aug 2026 |
| Minimal | Everything else | No mandatory requirements under the Act, except Article 4 AI literacy, which applies at every tier | — | Art. 4 since 2 Feb 2025 |
The tiers are not mutually exclusive
A high-risk recruitment tool that also talks to candidates owes Chapter III and Article 50. Reading the tiers as a single-choice classification is the most common structural error, and it produces compliance plans with a hole in them.
General-purpose AI models sit outside this table. Chapter V (Articles 51–56) applies to model providers on its own terms, has applied since 2 August 2025, and was not changed in substance by the Omnibus. GPAI obligations →
Every application date
- 2 Feb 2025 applies
Article 5 prohibited practices (original list). Article 4 AI literacy.
- 2 Aug 2025 applies
General-purpose AI model obligations, Chapter V (Arts. 51–55).
- 2 Aug 2026 applies
Article 50 transparency. Article 49 registration. National market surveillance authority powers. General application date.
- 2 Dec 2026 next
Two new Article 5 prohibitions (NCII/NCIM and CSAM generation). Article 50(2) machine-readable marking for generative systems already on the market before 2 Aug 2026.
- 2 Aug 2027 upcoming
National regulatory sandboxes (deferred by Reg. 2026/1744).
- 2 Dec 2027 upcoming
Annex III stand-alone high-risk obligations — Chapter III Sections 1, 2 and 3.
- 2 Aug 2028 upcoming
Annex I embedded high-risk obligations (AI in regulated products).
- 2 Aug 2030 upcoming
Article 111 transition ends for AI systems already in use by public authorities.
What the Omnibus deferred, precisely
The deferral concerns Chapter III Sections 1, 2 and 3: classification, requirements and provider obligations for high-risk systems. It did not defer the Article 5 prohibitions, Chapter V general-purpose AI, Article 50 transparency, Article 49 registration, or the general application date of 2 August 2026.
Expert analysis: commentary frequently collapses “the AI Act was delayed” with “the high-risk chapter was deferred”. They are not the same statement and the difference is roughly the whole of your live obligation set.
The high-risk obligations, article by article
These apply from 2 December 2027 for stand-alone Annex III systems. Each links to a full guide.
| Article | Obligation | The part most often missed |
|---|---|---|
| Art. 9 | Risk management system | Risk to people, not to the organisation. Information to deployers is the last resort in the hierarchy of measures. |
| Art. 10 | Data and data governance | The original purpose for which personal data was collected must be documented. |
| Art. 11 | Technical documentation (Annex IV) | Nine prescribed headings, kept up to date, retained ten years. |
| Arts. 12–13 | Logging; instructions for use | Six-month retention falls on provider and deployer, each for logs under their control. |
| Art. 14 | Human oversight | Five specific capabilities, including the authority to override. |
| Art. 15 | Accuracy, robustness, cybersecurity | Five AI-specific attack classes named in the Regulation itself. |
| Art. 17 | Quality management system | Thirteen enumerated elements. ISO/IEC 42001 does not satisfy it. |
| Arts. 43–48 | Conformity assessment, declaration, CE marking | Internal control for most Annex III. Not automatable. |
| Art. 49 | EU database registration | Applies even if you claim the Article 6(3) derogation. |
| Art. 72 | Post-market monitoring | The plan sits inside the Annex IV file and is examined before launch. |
| Art. 73 | Serious incident reporting | 15 days, 10 days for death, 2 days for widespread infringement. |
Deployers owe a separate, shorter set under Article 26, plus Article 27 fundamental rights impact assessments for public bodies and certain essential-service deployers. The full split →
Penalties
| Infringement | Maximum | Basis |
|---|---|---|
| Article 5 prohibited practices | €35M or 7% | Art. 99(3) |
| Other operator / notified body obligations, includes high-risk requirements and Article 50 | €15M or 3% | Art. 99(4) |
| Incorrect, incomplete or misleading information to authorities | €7.5M or 1% | Art. 99(5) |
| GPAI model provider obligations (Commission-enforced) | €15M or 3% | Art. 101 |
Whichever is higher, except for SMEs and start-ups, where the lower applies. Penalties in detail, with calculator →
Where to start, honestly
Practical recommendation. The hard part of AI Act compliance is not the documentation template. It is finding every AI system in the organisation, deciding what each one is, and keeping that current as new systems ship. That work does not get easier by waiting for standards, and it gates everything else.
- Inventory. Every system, every surface. Record intended purpose, role, tier and owner.
- Fix what is live. Article 50 disclosure and Article 4 literacy are in force now and carry penalties.
- Classify. Annex III exposure, and whether Article 6(3) genuinely applies. The derogation →
- Build the file. For anything high-risk, Annex IV and the Article 9 risk file are the long lead items.
Status labels on this page
Verified fact: The tiers, dates, article obligations and penalty tiers set out above, checked against the consolidated Regulation and the Commission's AI Act Service Desk.
Expert analysis: The ordering advice, the observation about tiers not being mutually exclusive, and the 'inventory first' recommendation.
Unsettled: Harmonised standards remain in development, which affects how several Chapter III requirements will be evidenced in practice.
From understanding to evidence
Every obligation above resolves to an artefact someone can inspect. The organisations that find this manageable are the ones that built a system to produce those artefacts rather than a project to write them once.
Not sure where you sit?
The classifier maps your system against Articles 5, 6, 50 and Annex III. Twelve questions, no email.
Frequently asked
What is the EU AI Act?
The EU AI Act is Regulation (EU) 2024/1689, the European Union's horizontal law on artificial intelligence. It was published in the Official Journal on 12 July 2024 and entered into force on 1 August 2024.
It classifies AI systems by risk and attaches proportionate obligations: prohibited practices under Article 5, high-risk systems under Article 6 and Annexes I and III, transparency obligations under Article 50, and a separate regime for general-purpose AI models in Chapter V. It was amended by Regulation (EU) 2026/1744, the Digital Omnibus on AI, which was published in the Official Journal on 24 July 2026 and entered into force on 27 July 2026.
Is the EU AI Act in force?
Yes. It entered into force on 1 August 2024 and applies in phases. Article 5 prohibitions and Article 4 AI literacy have applied since 2 February 2025. General-purpose AI model obligations have applied since 2 August 2025. Article 50 transparency, Article 49 registration and national market surveillance authority powers have applied since 2 August 2026. Obligations for stand-alone Annex III high-risk systems apply from 2 December 2027 and for Annex I embedded high-risk systems from 2 August 2028.
What are the four risk tiers of the EU AI Act?
Unacceptable risk, covered by the Article 5 prohibitions; high risk, covered by Article 6 with Annexes I and III and the requirements in Chapter III Section 2; limited or transparency risk, covered by the Article 50 disclosure duties; and minimal risk, which carries no mandatory requirements under the Act other than the Article 4 AI literacy duty which applies at every tier. General-purpose AI models sit alongside this structure in Chapter V rather than inside it.
What are the penalties under the EU AI Act?
Article 99 sets tiered maxima. Breach of the Article 5 prohibitions: up to 35 million euro or 7 percent of total worldwide annual turnover, whichever is higher. Breach of other operator or notified body obligations, which includes the high-risk requirements and Article 50 transparency: up to 15 million euro or 3 percent. Supplying incorrect, incomplete or misleading information to authorities: up to 7.5 million euro or 1 percent. Article 101 covers general-purpose AI model providers at up to 15 million euro or 3 percent, enforced by the Commission.
Does the EU AI Act apply to companies outside the EU?
Yes. Article 2 applies the Regulation to providers placing AI systems on the EU market or putting them into service in the EU irrespective of where they are established, and to providers and deployers in third countries where the output produced by the AI system is used in the EU. Regulation (EU) 2026/1744 did not narrow this territorial scope.
Guides by role and by sector
The obligations are the same; what lands on your desk is not. These take the same Regulation from a specific starting point.
By role. Board & executive · General counsel · CISO · DPO · CTO · Product manager · Internal audit · Consultants & advisers
By sector. HR & recruitment · Financial services · Insurance · MedTech · Manufacturing · Automotive · B2B SaaS · Law firms · Public sector · Startups & SMEs
Proving it to a buyer. AI governance in procurement · Microsoft SSPA Section K · AI system inventory · Vendor due diligence · Supplier programme · Third-party AI risk · Contract clauses · Maturity self-assessment · AI risk library
Edge cases and scope questions. Open-source exemptions · Regulatory sandboxes (Art. 57) · Global AI regulation · Territorial scope
How this site works. About & funding · Editorial standards · Glossary · Article index