Article-by-article breakdown

EU AI Act

Regulation (EU) 2024/1689 of the European Parliament and of the Council laying down harmonised rules on artificial intelligence

Chapter I — General provisions

Article 3Definitions

Applies from: 2 February 2025

Applies to

  • All providers, deployers, importers, and distributors of AI systems

Plain English

Article 3 is the dictionary of the Act. Two definitions matter most.

First, 'AI system' is defined broadly: a machine-based system that, with varying degrees of autonomy, may exhibit adaptiveness after deployment, and that infers from inputs how to generate outputs (predictions, content, recommendations, or decisions) that can influence physical or virtual environments. The Commission has explicitly clarified that simple deterministic software (e.g. spreadsheet formulas, rule-based systems without inference) is NOT in scope.

Second, the 'provider' vs 'deployer' distinction runs through the whole Act. A provider develops the AI system or has it developed and places it on the market under its own name. A deployer uses an AI system in a professional context. Different obligations attach to each — and a single company can be both at once (e.g. a fintech that builds and uses its own credit-scoring model).

Key points

  • Definition of 'AI system' aligns closely with the OECD's updated 2023 definition.
  • Deterministic, non-learning, non-inferring software is generally excluded.
  • 'Provider' vs 'deployer' is a recurring distinction — get this right early.
  • 'General-purpose AI model' is defined separately (Article 3(63)) — triggers the GPAI obligations in Chapter V.

What you need to do

  1. 1.Map each of your AI systems and tag whether you are the provider, the deployer, or both.
  2. 2.Don't try to escape the Act by calling your system 'just rules' — if it infers, it's in scope.
Chapter II — Prohibited AI practices

Article 5Prohibited AI practices

Applies from: 2 February 2025

Applies to

  • All providers and deployers of AI systems used in the EU

Plain English

Article 5 lists AI practices the EU has decided are too dangerous to ever permit. They are banned outright — no risk assessment will save you. There are 8 prohibited categories.

The most consequential bans for businesses are: (1) AI that uses subliminal or manipulative techniques to materially distort behaviour and cause harm; (2) AI that exploits vulnerabilities of specific groups (children, people with disabilities, those in poverty); (3) social scoring by public authorities; (4) untargeted scraping of facial images from the internet or CCTV to build face recognition databases; (5) emotion recognition in workplaces and schools; (6) biometric categorisation to infer race, political views, religion, or sexual orientation; and (7) most real-time remote biometric identification in public spaces by law enforcement (with narrow exceptions).

Fines for Article 5 violations are the highest in the Act: up to €35M or 7% of worldwide annual turnover, whichever is higher.

Key points

  • Bans apply from 2 February 2025 — first deadline of the Act.
  • The 'social scoring' ban primarily targets public-authority use; private-sector loyalty programs are generally OK.
  • Workplace and school emotion recognition is banned even for productivity / wellbeing use cases. Medical and safety reasons are exempted.
  • The face-database ban (Clearview-style) applies retroactively in effect — you must stop and delete.

What you need to do

  1. 1.Audit your AI tools for any of the 8 categories before 2 Feb 2025.
  2. 2.If you operate emotion-recognition or biometric-categorisation features in EU workplaces or schools — turn them off.
  3. 3.If you've trained on scraped facial images — review and prepare to defend the lawfulness.

Cross-jurisdiction equivalents

Colorado AI ActNo equivalent bans — Colorado regulates 'high-risk' AI but does not prohibit categories.
China Generative AI MeasuresArticle 4Prohibits content that 'incites subversion of state power' or undermines national security — different framing, different prohibitions.
Chapter III — High-risk AI systems

Article 6Classification rules for high-risk AI systems

Applies from: 2 August 2026

Applies to

  • Providers of AI systems that may fall into the high-risk category

Plain English

Article 6 is the gate to the heaviest part of the Act. An AI system is 'high-risk' if it either: (a) is a safety component of a product covered by the EU harmonisation legislation listed in Annex I (e.g. medical devices, machinery, toys, in-vitro diagnostics) AND requires a third-party conformity assessment under that legislation; OR (b) falls into one of the use-case categories in Annex III.

Annex III lists 8 high-risk areas: biometrics, critical infrastructure, education and vocational training, employment and workforce management, access to essential private and public services (including credit-scoring and welfare benefits), law enforcement, migration and border control, and administration of justice and democratic processes.

There is a 'lite' carve-out (Article 6(3)): if an Annex III system 'does not pose a significant risk of harm to the health, safety or fundamental rights of natural persons' — for example, it performs a narrow procedural task or improves the result of a previous human activity — the provider may document that conclusion and avoid full high-risk obligations. The Commission was meant to issue guidelines on this carve-out by Feb 2026.

Key points

  • Annex III lists the 8 high-risk use-case categories — read it before assuming you're out of scope.
  • Medical-device AI and AI in machinery are high-risk via Annex I, not Annex III.
  • The Article 6(3) carve-out is real but narrow — document the analysis carefully if you rely on it.
  • Misclassifying down ('I'm not high-risk') carries the second-highest fine tier: €15M or 3% of turnover.

What you need to do

  1. 1.For each AI system, walk through Annex I and Annex III explicitly and document the conclusion.
  2. 2.If you rely on the Article 6(3) carve-out, write down why with reference to the criteria.
  3. 3.Keep this analysis updated when the system's purpose changes.

Cross-jurisdiction equivalents

Colorado AI ActSec. 6-1-1701(3)Colorado defines 'consequential decisions' across similar domains (employment, finance, healthcare, etc.) but the threshold and obligations differ.
Chapter III, Section 2 — Requirements for high-risk AI systems

Article 9Risk management system

Applies from: 2 August 2026

Applies to

  • Providers of high-risk AI systems

Plain English

If your AI system is high-risk, you must establish, implement, document, and maintain a risk management system. It is not a one-off compliance exercise — it runs across the entire lifecycle of the system and must be updated regularly.

The minimum process: identify and analyse known and reasonably foreseeable risks; estimate and evaluate risks that may emerge when the system is used as intended or under conditions of reasonably foreseeable misuse; evaluate other risks discovered through post-market monitoring; adopt risk-management measures that eliminate or mitigate risks to an acceptable level.

Special attention is required for impact on persons under 18 and other vulnerable groups. The system as a whole — when considered with the risk-management measures — must achieve 'acceptable risk' (Article 9(3)).

Key points

  • It's a continuous process, not a one-time document.
  • Must cover both intended use AND reasonably foreseeable misuse.
  • Vulnerable groups (minors, etc.) get explicit consideration.
  • Post-market monitoring (Article 72) feeds back into the risk management system.

What you need to do

  1. 1.Designate an owner (usually a Compliance / Quality function) and a process for reviewing risks at least annually.
  2. 2.Connect this to your existing ISO 27001 / ISO 23894 / NIST AI RMF processes — don't build a parallel system.
  3. 3.Document each risk-management decision; the audit trail matters.

Cross-jurisdiction equivalents

Colorado AI ActSec. 6-1-1703(2)Required: deployer risk management policy and program, reviewed annually. Less prescriptive than the EU.
NIST AI RMF (US guidance)Voluntary, but maps closely. Using the NIST AI RMF helps satisfy Article 9 in practice.
Chapter III, Section 2

Article 10Data and data governance

Applies from: 2 August 2026

Applies to

  • Providers of high-risk AI systems that train on data

Plain English

Training, validation, and testing datasets used for high-risk AI must meet quality criteria. They must be relevant, sufficiently representative, free of errors to the extent feasible, and complete for the intended purpose. Datasets must take into account the geographical, contextual, behavioural, or functional setting in which the system will be used.

For systems that use techniques to detect or correct bias, providers may process special-category personal data (Article 9 GDPR) under strict conditions — including a documented necessity, deletion after bias detection, and no transfer to third parties (Article 10(5)).

Data-governance practices must cover design choices, data collection and preparation, annotation, labelling, examination for biases that may affect health, safety, or fundamental rights, and gap-filling.

Key points

  • Data quality is a hard requirement, not a 'best effort' suggestion.
  • You may process sensitive personal data SOLELY for bias detection, under strict controls.
  • Documentation of data lineage is expected.
  • Datasets must match the deployment context — US-trained data for EU deployment may not pass.

What you need to do

  1. 1.Document where your training data came from, how it was cleaned, how it was labelled, and how you tested for bias.
  2. 2.Don't use special-category data for bias detection without legal review.
  3. 3.If you operate in multiple regions, validate the model on representative data from each.

Cross-jurisdiction equivalents

GDPRArticles 5, 9Article 10(5) of the AI Act is the express interface with GDPR Article 9 special-category processing.
Chapter III, Section 2

Article 13Transparency and provision of information to deployers

Applies from: 2 August 2026

Applies to

  • Providers of high-risk AI systems

Plain English

Article 13 says: tell your customers (deployers) enough about the system so they can use it safely. You must provide instructions for use that include the system's identity and contact details, intended purpose and expected accuracy, known limitations, training data characteristics in summary, technical capabilities and features needed to interpret outputs, human oversight measures, expected lifespan, and maintenance / updates.

This is the article that creates the documentation that ends up in your customer's compliance file. It is also what enables Article 26 deployer obligations to be met — without this information, the deployer can't comply.

Key points

  • Detailed instructions for use are mandatory and must be in the language of the deployer's Member State.
  • Drives the contractual chain from provider to deployer to end user.
  • Failure here propagates downstream — your customer's non-compliance becomes a defensive lever against you.

What you need to do

  1. 1.Write proper user documentation. The product-spec PDF you already have is probably not enough.
  2. 2.Translate. The Act doesn't tolerate English-only documentation when deployers are in non-English-speaking Member States.
Chapter III, Section 2

Article 14Human oversight

Applies from: 2 August 2026

Applies to

  • Providers of high-risk AI systems

Plain English

High-risk AI systems must be designed so a human can effectively oversee them. The Act lists what 'effective oversight' means: the human can understand the system's capacities and limitations, monitor its operation, detect anomalies and dysfunctions, correctly interpret outputs, decide not to use the output, and intervene or stop the system.

For remote biometric identification (Article 14(5)), the deployer cannot act on an identification unless two natural persons have separately verified and confirmed it — a 'two human signoff' rule.

Key points

  • Oversight must be 'effective', not just present — the human must actually be able to override.
  • The classic anti-pattern (UI shows the AI's answer, human rubber-stamps) won't pass.
  • Biometric ID requires two independent humans to confirm.

What you need to do

  1. 1.Design the workflow so the human-in-the-loop has the time, information, and authority to override.
  2. 2.Train your operators. Article 14 obligations include training and qualifications.
  3. 3.Log overrides for post-market analysis.
Chapter III, Section 3 — Obligations of providers and deployers

Article 26Obligations of deployers of high-risk AI systems

Applies from: 2 August 2026

Applies to

  • Deployers (users in professional contexts) of high-risk AI systems

Plain English

Deployers — not just developers — have direct obligations. You must use the system in accordance with the provider's instructions, ensure input data is relevant and representative, monitor the system and inform the provider of risks, suspend use when you suspect the system poses risk, keep logs (for at least 6 months), inform affected workers when you use a workplace AI system, and complete a fundamental rights impact assessment for some deployments (Article 27).

This matters because most companies are deployers, not providers. If you license an AI tool and use it for hiring, that tool's vendor handled the provider obligations — but Article 26 puts duties directly on you.

Key points

  • Affects every business deploying licensed high-risk AI — not just AI vendors.
  • Workers must be informed before a workplace AI is rolled out (Art. 26(7)).
  • Public-sector deployers and certain private deployers in essential services must do a Fundamental Rights Impact Assessment (FRIA, Article 27).
  • Logs must be kept for at least 6 months (or longer if national law requires).

What you need to do

  1. 1.Inventory every high-risk AI system in use. Treat licensed tools as in-scope.
  2. 2.Build the FRIA into your existing DPIA process for public-sector and essential-service uses.
  3. 3.Update employment communications: if you use AI in hiring or HR, tell employees before you deploy.

Cross-jurisdiction equivalents

Colorado AI ActSec. 6-1-1703Colorado's deployer obligations (impact assessments, risk management, consumer notice) align closely with Article 26.
Chapter IV — Transparency obligations

Article 50Transparency obligations for certain AI systems

Applies from: 2 August 2026

Applies to

  • Providers and deployers of: chatbots, emotion recognition, biometric categorisation, generative AI

Plain English

Article 50 covers the 'limited risk' tier — AI systems that aren't high-risk but interact with people directly enough that disclosure is warranted.

Four categories: (1) chatbots — users must be informed they are interacting with an AI unless that's obvious; (2) emotion recognition or biometric categorisation systems — the natural persons exposed must be informed; (3) deepfakes — content depicting real people, places, or events that has been artificially generated or manipulated must be clearly labelled; (4) generative text used to inform the public on matters of public interest — must be disclosed as AI-generated unless human-reviewed and a publisher takes editorial responsibility.

Labels on AI-generated images, audio, and video should be machine-readable where technically feasible (think: C2PA-style watermarking).

Key points

  • These rules apply even to non-high-risk systems.
  • Deepfake labelling has a journalistic / public-interest exception when content is human-reviewed.
  • Machine-readable labelling is expected for AI-generated media.
  • Penalties for non-compliance under Article 99 — up to €15M or 3% of turnover.

What you need to do

  1. 1.Add a 'You're talking to an AI' notice to chatbots. Don't bury it in the ToS.
  2. 2.If you generate synthetic media, implement visible + metadata labels.
  3. 3.Document the editorial-review process if you rely on the publisher exception.

Cross-jurisdiction equivalents

China Generative AI MeasuresArticle 12China imposes similar labelling on AI-generated images, video, and audio — sometimes more prescriptive.
Chapter V — General-purpose AI models

Articles 51-55General-purpose AI models (and systemic risk)

Applies from: 2 August 2025

Applies to

  • Providers of general-purpose AI models (foundation models like GPT-class systems)

Plain English

Chapter V deals with general-purpose AI models — what most people call 'foundation models'. Every GPAI provider has baseline obligations: maintain technical documentation, provide information to downstream providers, comply with EU copyright law, and publish a sufficiently detailed summary of the training data.

If the model exceeds the systemic-risk threshold — currently 10^25 floating-point operations of training compute — the obligations escalate sharply: model evaluations (including adversarial testing / red-teaming), risk assessment and mitigation, serious-incident reporting to the AI Office, cybersecurity protection for the model and physical infrastructure, and notification to the Commission within 2 weeks of crossing the threshold.

Providers of open-source GPAI models get a partial exemption from the documentation and downstream-information obligations — but NOT from the systemic-risk obligations if they cross the compute threshold.

Key points

  • The 10^25 FLOPs threshold currently captures the top handful of frontier models.
  • Training-data summary is a hard requirement, even for closed models.
  • Open-source exemption is narrow — it does not extend to systemic-risk models.
  • Notification to the Commission within 2 weeks of crossing the threshold.

What you need to do

  1. 1.If you train models above 10^24 FLOPs, monitor compute carefully — crossing 10^25 triggers obligations.
  2. 2.Maintain training-data documentation from day one. Retro-fitting is painful.
  3. 3.Even if you're below the threshold, the baseline documentation obligations still apply.

Cross-jurisdiction equivalents

California SB 1047 (vetoed)Sec. 22602-22603Would have applied similar duties (safety protocol, kill switch, incident reporting) above a higher 10^26 threshold. Vetoed Sept 2024.
Chapter XII — Penalties

Article 99Penalties

Applies from: 2 August 2025 (for GPAI), 2 August 2026 (for high-risk), 2 February 2025 (for prohibitions)

Applies to

  • All non-compliant providers, deployers, importers, distributors

Plain English

Three penalty tiers. Tier 1 (the highest): violation of the Article 5 prohibitions — up to €35,000,000 or, if the offender is a company, 7% of worldwide annual turnover, whichever is higher. Tier 2: violation of other AI Act obligations (Articles 16-29 provider/deployer duties, GPAI duties, etc.) — up to €15,000,000 or 3% of worldwide annual turnover. Tier 3: supplying incorrect, incomplete, or misleading information to authorities — up to €7,500,000 or 1% of turnover.

SMEs (including startups) get a more favourable calculation: the lower of the absolute amount and the percentage applies, not the higher. National authorities also have discretion to lower fines proportionate to economic viability.

Key points

  • Tier 1 (7% / €35M) is reserved for prohibited-practice violations — Article 5.
  • Tier 2 (3% / €15M) covers the bulk of compliance failures.
  • Misleading authorities is itself a violation.
  • SMEs and startups get a lighter calculation — but the floor is still meaningful.

What you need to do

  1. 1.Treat the Article 5 ban-list as the highest-stakes audit area.
  2. 2.Don't make incorrect declarations to authorities — Tier 3 attaches to that alone.
  3. 3.Build a budget assumption for at least Tier 2 exposure on every high-risk deployment.

Cross-jurisdiction equivalents

GDPRArticle 83GDPR caps at 4% of turnover / €20M. The AI Act goes higher for Article 5 violations.

Need help applying this to your case?

The wizard takes 60 seconds and tells you which articles you actually need to worry about based on your jurisdictions, use case, and data.

Start the wizard →