EU AI Act FAQ
Twenty questions, answered as briefly as accuracy allows, each linked to the detail. Reflects Regulation (EU) 2024/1689 as amended by Regulation (EU) 2026/1744.
The amendment and the dates
Was the EU AI Act delayed?
Partly and precisely. Regulation (EU) 2026/1744 deferred Chapter III Sections 1 to 3 high-risk obligations to 2 December 2027 for stand-alone Annex III systems and 2 August 2028 for Annex I embedded systems. It did not defer the Article 5 prohibitions, Article 4 AI literacy, the Chapter V general-purpose AI regime, Article 49 registration or the Article 50 transparency obligations.
What applies right now?
Article 5 prohibitions and Article 4 AI literacy since 2 February 2025. General-purpose AI model obligations since 2 August 2025. Article 50 transparency, Article 49 registration and national market surveillance authority enforcement powers since 2 August 2026.
What is the next deadline?
2 December 2026. Two new Article 5 prohibitions covering non-consensual intimate material and child sexual abuse material generation, and Article 50(2) machine-readable marking for generative systems already on the market before 2 August 2026.
Does it apply outside the EU?
Yes. Article 2 catches providers placing systems on the EU market irrespective of establishment, and providers and deployers in third countries where the output produced by the system is used in the Union.
Penalties
What are the penalties?
Article 99(3): up to 35 million euro or 7 percent of worldwide annual turnover for Article 5 prohibitions. Article 99(4): up to 15 million euro or 3 percent for other operator obligations including high-risk requirements and Article 50 transparency. Article 99(5): up to 7.5 million euro or 1 percent for misleading information to authorities. Article 101: up to 15 million euro or 3 percent for general-purpose AI model providers.
Is 35 million euro or 7 percent the fine for high-risk?
No. That is the Article 99(3) maximum for breaching the Article 5 prohibitions only. High-risk non-compliance and transparency breaches fall under Article 99(4) at up to 15 million euro or 3 percent. This is the most common error in AI Act commentary.
High-risk classification
How do I know if my system is high-risk?
Two routes. Article 6(1) with Annex I, where the AI is a safety component of or is itself a product requiring third-party conformity assessment, applying from 2 August 2028. Article 6(2) with Annex III, where the intended purpose falls within one of eight listed areas, applying from 2 December 2027, subject to the Article 6(3) derogation.
Can an Annex III system avoid high-risk classification?
Through the Article 6(3) derogation, where it does not pose a significant risk of harm including by not materially influencing the outcome of decision-making, and meets one of four conditions. An Annex III system is always high-risk where it performs profiling of natural persons, which removes the derogation for most systems that evaluate people.
Standards and certification
Does ISO 42001 make us EU AI Act compliant?
No. ISO/IEC 42001 is not a harmonised standard and confers no Article 40 presumption of conformity. CEN-CENELEC JTC 21 assessed it against the Article 17 quality management requirement, found it misaligned, and developed EN 18286 instead. It remains valuable for organisational governance and for procurement.
Are there any harmonised standards yet?
No. As at the last review of this page, no CEN-CENELEC deliverable had been cited in the Official Journal, so none confers Article 40 presumption. EN 18286 on quality management is the most advanced, having passed Enquiry and reached the Approval stage.
Transparency and AI literacy
Does Article 50 apply to a minimal-risk chatbot?
Yes. Article 50 attaches to what a system does rather than to its risk tier. A minimal-risk chatbot that interacts with people is within Article 50(1) unless the AI interaction is obvious to a reasonably well-informed, observant and circumspect person in the circumstances.
Is a footer disclaimer enough for Article 50?
Article 50(5) requires clear and distinguishable information at the latest at the time of first interaction or exposure. A footer line or terms-of-service clause is unlikely to satisfy wording expressed in those terms. This is our reading; no enforcement decisions exist.
What changed for AI literacy?
Regulation (EU) 2026/1744 replaced Article 4 in full. The duty changed from ensuring a sufficient level of AI literacy to taking measures to support its development, with an express statement that no particular level need be guaranteed. It was not deferred and still binds every provider and deployer at every risk tier.
Roles and responsibilities
Do we become a provider by building on a foundation model?
You can. Article 25 makes a party a provider of a high-risk AI system where it puts its name or trade mark on such a system, makes a substantial modification to one, or modifies the intended purpose of a system including a general-purpose AI system so that it becomes high-risk.
Who has to do a FRIA?
Deployers that are bodies governed by public law, private entities providing public services, and deployers of Annex III point 5(b) creditworthiness systems and point 5(c) life and health insurance systems. It is performed before first use and the results are notified to the market surveillance authority.
Operating obligations
How quickly must a serious incident be reported?
Within 15 days of becoming aware as a default, 2 days for a widespread infringement or serious and irreversible disruption of critical infrastructure, and 10 days where a death may have been caused. Article 73(5) permits an incomplete initial report followed by a complete one.
Can conformity assessment be automated or outsourced?
No. For most Annex III systems it is carried out by the provider under internal control against Annex VI, and the provider draws up and signs the EU declaration of conformity under Article 47. Evidence assembly can be systematised; the assessment and the declaration cannot be delegated to software or to an adviser.
Does CE marking apply to software?
Yes, for high-risk AI systems. Article 48 requires CE marking, and for systems provided digitally it may be affixed digitally where it can be accessed easily through the interface or a machine-readable code.
Practicalities
Which authority regulates us?
National market surveillance authorities designated by each member state enforce most of the Regulation, with the Commission's AI Office responsible for general-purpose AI models and holding exclusive competence in defined cases. Designation status varies by member state and public sources conflict on several.
Where do we start?
An AI system inventory. Every obligation, every classification decision and every customer questionnaire depends on knowing which systems you have, what each is for, and which role you are in for each one.
Where to go next
Understand it
Apply it
Prove it
If an answer here is wrong
Tell us. We fix errors and publish what changed rather than editing silently, and we have already issued two corrections during this site’s rebuild. Report an error →
Guides by role and by sector
The obligations are the same; what lands on your desk is not. These take the same Regulation from a specific starting point.
By role. Board & executive · General counsel · CISO · DPO · CTO · Product manager · Internal audit · Consultants & advisers
By sector. HR & recruitment · Financial services · Insurance · MedTech · Manufacturing · Automotive · B2B SaaS · Law firms · Public sector · Startups & SMEs
Proving it to a buyer. AI governance in procurement · Microsoft SSPA Section K · AI system inventory · Vendor due diligence · Supplier programme · Third-party AI risk · Contract clauses · Maturity self-assessment · AI risk library
Edge cases and scope questions. Open-source exemptions · Regulatory sandboxes (Art. 57) · Global AI regulation · Territorial scope
How this site works. About & funding · Editorial standards · Glossary · Article index