Appearance
EU AI Act
The EU AI Act — Regulation (EU) 2024/1689 — is the European Union's horizontal regulation on artificial intelligence. It governs AI systems in context (model + pipeline + human process + deployment environment) and general-purpose AI models as a separate regime, with directly applicable obligations across every Member State.
Quick decision
- Just want to know if your AI system is in scope → if you place an AI system on the EU market, put one into service in the Union, or use the output in the Union, the Regulation applies under Article 2. Designate an authorised representative under Article 22 if you are a non-EU provider of a high-risk system.
- Building or shipping a high-risk AI system → the substantive Articles 8–15 obligations bite. See High-risk AI systems.
- Building or deploying a chatbot, emotion-recognition system, biometric categoriser, or anything that outputs deepfakes / synthetic media → Article 50 transparency duties apply independently of high-risk classification. See Prohibited practices and transparency.
- Provider of a general-purpose AI model → Chapter V (Articles 51–56) applies at the model level. The 10²⁵ FLOPs training-compute threshold triggers the systemic-risk regime. See General-purpose AI models.
- Worried the four-tier pyramid you read about everywhere is misleading → good. The Regulation does not use that framing. See Common misreadings of the AI Act below.
TL;DR
- Regulation (EU) 2024/1689; OJ L of 12 July 2024; CELEX
32024R1689. Entered into force 1 August 2024. - Four obligation regimes can apply to the same system, independently and stacking: Article 5 prohibited practices; Article 6 + Annex I / III high-risk; Article 50 transparency on specific deployments; Chapter V GPAI at model level.
- "Limited risk" and "minimal risk" are not defined categories in the Regulation. They are journalistic shorthand. See Common misreadings.
- Article 4 AI literacy applies to all providers and deployers of any AI system — not just high-risk — from 2 February 2025. The four regimes above govern system-classification obligations; Article 4 sits on top of them.
- Phased application: Article 5 prohibited practices from 2 February 2025; Chapter V GPAI from 2 August 2025. The June 2026 Digital Omnibus (adopted, not yet in force) will, once in force, defer the high-risk deadlines to 2 December 2027 (Annex III standalone) and 2 August 2028 (Annex I product-safety), replacing the original 2 August 2026 / 2 August 2027 dates; two new Article 5 prohibitions (NCII, CSAM) will apply from 2 December 2026.
- Penalties under Article 99 reach up to €35 million or 7% of worldwide annual turnover for Article 5 infringements; up to €15 million or 3% for most other obligations on operators.
- Modulos operationalises the AI Act through the OFF-1 (organisation) and MFF-1 (AI application) framework templates; GPAI is folded into MFF-1 via the scoping questionnaire, not a separate template.
Digital Omnibus on AI (adopted June 2026)
Status: adopted, not yet in force (June 2026)
The Digital Omnibus on AI has been adopted. The European Parliament approved the agreed text on 16 June 2026 (423 votes to 57, with 174 abstentions; legislative resolution P10_TA(2026)0198), and the Council formally adopted it on 29 June 2026, closing procedure 2025/0359(COD) (Commission proposal COM(2025) 836 of 19 November 2025). On entry into force the Regulation will amend Regulations (EU) 2024/1689 (AI Act), (EU) 2018/1139 and (EU) 2023/1230; it enters into force on the third day after its publication in the Official Journal (not yet published as of this writing).
These amendments have been adopted and will supersede the original Regulation (EU) 2024/1689 dates where they amend them once the Omnibus enters into force. On entry into force, the substantive effects for the AI Act will be:
- High-risk application dates move to fixed new deadlines — standalone Annex III obligations (Article 6(2)) will move from 2 August 2026 to 2 December 2027; product-safety Annex I obligations (Article 6(1)) will move from 2 August 2027 to 2 August 2028 (Article 113, as amended). Fixed application dates will replace the Commission's original readiness-decision model.
- Two new prohibited practices — Article 5(1) will gain point (ba) (AI generating non-consensual intimate imagery) and point (bb) (AI generating child sexual abuse material). Both will apply from 2 December 2026.
- Article 50(2) synthetic-content marking — four-month grace — providers of synthetic-content AI systems already placed on the EU market before 2 August 2026 will have until 2 December 2026 to meet the Article 50(2) provider-side machine-readable marking duty (new Article 111(4)). Deployer-side Article 50(4) disclosure is not extended.
- Annex III non-high-risk registration retained but simplified — providers that determine an Annex III use case is not high-risk will still register it in the EU database, with reduced content requirements (Annex VIII, Section B points 7 and 9 deleted).
- National regulatory sandboxes — deadline 2 August 2027 — each Member State will need to have at least one operational AI regulatory sandbox by 2 August 2027 (Article 57(1)), a one-year shift; the AI Office will also be able to run a Union-level sandbox.
- Bias-correction data basis kept and extended — a new Article 4a will retain the strict-necessity legal basis to process special-category personal data for bias detection and correction, and will extend it to deployers and to providers/deployers of other AI systems and models.
- AI literacy obligation recalibrated — Article 4 will require providers and deployers to "take measures to support the development of AI literacy", with no obligation to guarantee any specific level for any individual.
- Simplified compliance for SMEs and Small Mid-Caps (SMCs) — a new SMC definition (Commission Recommendation (EU) 2025/1099) will bring simplified technical documentation (Article 11) and proportionate quality-management obligations (Article 17) to SMEs, start-ups and SMCs, extend the lower-of fine cap to SMCs (Article 99(6a)), and add proportionality and viability considerations.
- AI Office given exclusive competence and enforcement powers — on entry into force, the AI Office will exclusively supervise AI systems built on general-purpose AI models where the model and system come from the same provider or the same undertaking (carve-outs for Annex I products, Annex III point 2 biometrics, law enforcement, border management, Annex III point 8 justice and financial institutions), and AI that constitutes or is integrated into a very large online platform or search engine; new Articles 75a–75d will give it full market-surveillance, fining and penalty powers.
- Sectoral overlaps resolved through delegated acts — where sectoral law in Section A of Annex I provides an equivalent level of protection, the Commission will be able to limit specific AI Act requirements via delegated acts (new Article 2(13); by 2 August 2027).
- Machinery moved to the sectoral track — the Omnibus deletes the Machinery Directive 2006/42/EC from Annex I Section A and adds the Machinery Regulation (EU) 2023/1230 to Annex I Section B (point 21) on entry into force; the Commission will add health-and-safety requirements for high-risk AI in machinery by delegated act, applicable by 2 August 2028.
These are the adopted amendments to plan against; they will bind once the Omnibus enters into force. For Modulos' public analysis, see modulos.ai/eu-ai-act/.
Primary sources
- AI Act — Regulation (EU) 2024/1689 of 13 June 2024, EUR-Lex CELEX
32024R1689· OJ L, 12.7.2024. - Digital Omnibus on AI — European Parliament position
P10_TA(2026)0198of 16 June 2026, procedure2025/0359(COD); Official Journal reference(EU) 2026/…to follow on publication.
Verbatim quotes on this page reflect the OJ-published 2024/1689 text; where the Digital Omnibus amends a provision, the amended wording will govern once the Omnibus enters into force.
Article 1 — subject matter
The purpose of this Regulation is to improve the functioning of the internal market and promote the uptake of human-centric and trustworthy artificial intelligence (AI), while ensuring a high level of protection of health, safety, fundamental rights enshrined in the Charter, including democracy, the rule of law and environmental protection, against the harmful effects of AI systems in the Union and supporting innovation.
— Article 1(1), Regulation (EU) 2024/1689
The Regulation is built on Articles 16 and 114 TFEU (data protection + internal market) with a fundamental-rights overlay. The result is product-safety mechanics (classification, conformity assessment, CE marking, post-market monitoring, market surveillance) anchored to a fundamental-rights protective purpose.
Article 3(1) — what counts as an 'AI system'
‘AI system’ means a machine-based system that is designed to operate with varying levels of autonomy and that may exhibit adaptiveness after deployment, and that, for explicit or implicit objectives, infers, from the input it receives, how to generate outputs such as predictions, content, recommendations, or decisions that can influence physical or virtual environments;
— Article 3(1), Regulation (EU) 2024/1689
This definition is system-level, not model-level. Compliance work includes the model, the surrounding pipeline, the human process, and the environment where outputs influence decisions.
AI system
The model is the centre. The system is everything around it.
Inputs
DataTraining data, input data, labels, feedback
InfrastructureCloud, third parties, model providers
InterfacesAPI, UI, integrations
AI system
Outputs that influence real decisions
The bounded technical artifact under governance.
Model or modelsFoundation model, fine-tune, classifier
Inference & orchestrationPrompting, retrieval, routing, post-processing
Operations
Humans in the loopOperators, reviewers, escalation paths
MonitoringDrift, quality, incidents
Downstream decisionsBusiness process, automation, approvals
Documentation & controlsPolicies, evals, evidence
An AI system includes the model, the surrounding pipeline, the human processes, and the environment where outputs drive real decisions.
If you only govern "the model", you will miss what auditors and regulators actually care about: data governance, deployment constraints, monitoring, human oversight, and traceability.
Background note (external): A taxonomy of AI systems and models in the EU AI Act.
Go deeper: the Commission has issued interpretive guidance on the Article 3(1) definition (Communication C(2025) 5053 final, 29 July 2025) decomposing the definition into seven elements and identifying four categories of systems that fall outside it.
Four obligation regimes (not a 'risk pyramid')
The Regulation defines four independent gates that can apply to the same AI system. Each gate has its own trigger; the same system can fire several at once and the obligations apply in parallel.
EU AI Act classification
Four independent gates. Obligations stack.
Gate 1 · Article 5
Prohibited practices
Does this AI practice cross a red line?
Banned. Narrow 5(1)(h) RBI carve-out under 5(2)–(7).
Gate 2 · Article 6
High-risk AI systems
Annex I product subject to third-party conformity assessment, or an Annex III use case (with the narrow Art. 6(3) derogation; profiling always high-risk)?
Articles 8–15 full compliance regime.
Gate 3 · Article 50
Transparency duties
Interacts, generates, recognises emotion, or biometrically categorises?
Disclosure / marking on the system or deployment.
Gate 4 · Chapter V
General-purpose AI models
Providing a foundation / GPAI model?
Model-level obligations (Articles 53–55).
Fires this gateProhibitedUpstream (different actor)Obligations stack
Worked examples
AI system
G1
G2
G3
G4
Combined effect
Credit-scoring chatbot
·
✓
✓
·
Annex III(5)(b) high-risk + Article 50(1) interaction disclosure
Customer-service bot
·
·
✓
·
Article 50(1) only
Medical-triage AI on a device
·
✓
✓
·
Annex I (medical-device) high-risk + Article 50(1) if patient-facing.
Workplace emotion recognition
✕
·
·
·
Prohibited under 5(1)(f). Stop.
Deepfake generator built on a GPAI
·
·
✓
up
System provider: Article 50(2) marking; deployer: Article 50(4) disclosure. Chapter V sits upstream on the GPAI model provider.
Important: these regimes stack, they don't tier
The Regulation does not describe a hierarchy. A high-risk AI system can also be subject to Article 50 transparency duties. A GPAI model can be deployed inside a high-risk AI system. "Limited risk" and "minimal risk" are not defined categories in the Regulation — see Common misreadings.
Classification flow
- Define the AI system and its intended purpose under Article 3(1).
- Article 5 prohibited? If the use case falls within Article 5(1)(a)–(h), the system cannot be deployed in the EU — except where a statutory exception applies (notably the 5(1)(h)(i)–(iii) real-time RBI law-enforcement objectives under the 5(2)–(7) authorisation regime). Outside those narrow exceptions, the route is redesign, scope-out, or stop.
- Article 6 high-risk? Article 6(1) covers AI systems that are themselves products, or safety components of products, covered by the Annex I Union harmonisation legislation (medical devices, machinery, vehicles, etc.) and required to undergo a third-party conformity assessment under that legislation. Article 6(2) covers Annex III standalone use cases (biometrics, critical infrastructure, education, employment, essential services, law enforcement, migration / border, justice / democratic processes). Articles 8–15 obligations apply across the lifecycle (for Annex I Section B products they are integrated through the sectoral act).
- Article 50 transparency applies independently to chatbots, emotion recognition, biometric categorisation, deepfakes, and AI-generated content — whether or not the system is high-risk.
- Built on a GPAI model? The upstream model provider has obligations under Articles 53–55 (transparency, copyright policy, downstream documentation; systemic-risk obligations if above 10²⁵ FLOPs). System-level obligations on the deployer are separate.
Go deeper: High-risk AI systems · Prohibited practices and transparency · General-purpose AI models.
Common misreadings of the AI Act
Public commentary about the Regulation is uneven. The frequent mistakes — most of them inherited from pre-final-text drafts — are worth calling out explicitly. Each is anchored to the Article that proves it wrong.
- "The AI Act is a four-tier risk pyramid (unacceptable / high / limited / minimal)." The Regulation does not use the word pyramid anywhere, and "limited" and "minimal" are not defined categories. Articles 5, 6, and 50 define three separate operative regimes that can stack on the same system; Chapter V (Articles 51–56) is a fourth, model-level regime that doesn't fit the visual hierarchy at all.
- "Limited risk = Article 50 transparency tier." Article 50 imposes transparency duties on specific deployments (chatbots, emotion recognition, biometric categorisation, deepfakes, AI-generated content). The system carrying those duties may also be high-risk. "Limited risk" is not a tier — it is shorthand for "Article 50 may apply".
- "Minimal risk systems must follow voluntary codes." The Regulation imposes no system-classification obligations outside the four regimes above. But Article 4 (AI literacy) applies to providers and deployers of any AI system — not only high-risk — from 2 February 2025. Voluntary codes of conduct under Article 95 are voluntary. The residual is "no Articles 5/6/50/Chapter V obligations", not "no AI Act obligations at all".
- "Prohibited = top of the pyramid; just the strictest tier of compliance." Article 5 prohibitions are bans with narrow statutory exceptions (most notably the conditional 5(1)(h) real-time RBI law-enforcement regime under 5(2)–(7)). There is no "compliance" route outside those exceptions — the operative duty is don't place on the market, don't put into service, don't use. Compliance-style framing for prohibited practices misleads.
- "Generative AI / foundation models are automatically high-risk." General-purpose AI models are regulated under Chapter V (Articles 51–56) at the model level, with their own provider obligations and systemic-risk threshold (10²⁵ FLOPs). High-risk classification under Article 6 is a system-level question driven by intended purpose; a GenAI model becomes part of a high-risk system only when integrated into one whose use case falls under Annex III or Annex I.
- "High-risk is one bucket." Article 6(1) covers AI systems that are safety components of products covered by Annex I sectoral law (medical devices, machinery, vehicles, …). Article 6(2) covers Annex III standalone use cases. The two routes have different conformity-assessment paths (Annex I Section A uses the Article 43(3) sectoral integration route; Section B follows the relevant sectoral regime where AI requirements are integrated; Annex III generally uses Annex VI internal control unless the system performs biometric identification).
- "Article 22 GDPR and Article 14 EU AI Act are the same human-oversight obligation." They are not. Article 14 is a design duty on providers of high-risk AI systems (oversight measures built into the system). Article 22 GDPR is a data-subject right against solely-automated decisions producing legal or similarly significant effects. The duties have different addressees, scopes, and remedies.
- "Article 33 GDPR and Article 73 EU AI Act are the same 72-hour breach duty." They are not. Article 33 GDPR governs notification of personal-data breaches to supervisory authorities. Article 73 EU AI Act governs reporting of serious incidents (death, serious harm to health, serious and irreversible disruption of critical infrastructure, infringement of fundamental rights) by providers of high-risk AI systems to market-surveillance authorities. Reporting deadlines differ and the events are different.
How this lands in Modulos
The active project setting is Use Case (High Risk / Limited Risk / Transparency), a deployment-context filter that scopes the active requirements set. It is not a legal high-risk classification. The Article 6 + Annex I / III rationale on the MFF-1 classification requirement is the legal answer. See Operationalizing in Modulos for the full settings surface.
Timeline
1 August 2024
Regulation (EU) 2024/1689 enters into force
2 February 2025
Original Article 5(1)(a)-(h) prohibited practices apply
2 August 2025
Chapter V GPAI provider obligations apply
2 December 2026
New Article 5 prohibitions (NCII, CSAM) will apply, and legacy synthetic-content systems must meet Article 50(2) marking, once the Omnibus enters into force
2 December 2027
Annex III standalone high-risk obligations will apply on 2 December 2027 once the June 2026 Digital Omnibus enters into force (deferred from 2 August 2026)
2 August 2028
Annex I product-safety high-risk obligations will apply on 2 August 2028 once the June 2026 Digital Omnibus enters into force (deferred from 2 August 2027)
Roles and responsibilities (at a glance)
The Regulation assigns obligations by legal role (Article 3 definitions). These are distinct from Modulos project roles (Owner, Editor, Reviewer, Auditor).
- Provider (Article 3(3)): develops or has developed an AI system or general-purpose AI model and places it on the EU market or puts it into service under its own name or trademark. Provider duties on high-risk AI systems sit in Article 16; provider duties on GPAI models sit in Article 53 (and additional duties for systemic-risk GPAI in Article 55).
- Deployer (Article 3(4); high-risk-system duties in Article 26): uses an AI system under its own authority (other than for personal non-professional activity).
- Importer (Article 3(6); duties in Article 23) and distributor (Article 3(7); duties in Article 24): make systems available in the EU supply chain.
- Authorised representative (Article 3(5)): represents non-EU providers in the Union. For high-risk AI systems the duties sit in Article 22; for GPAI model providers they sit in Article 54.
Article 25 — accidental provider
A deployer, importer, or distributor becomes a provider under Article 25 if it (a) puts its own name or trademark on a high-risk AI system, (b) makes a substantial modification to a high-risk AI system on the market, or (c) modifies the intended purpose of a non-high-risk AI system so that it becomes high-risk. The original provider's obligations transfer.
Go deeper: Roles and responsibilities.
High-risk obligations (at a glance)
For high-risk AI systems, Articles 8–15 impose continuous lifecycle obligations on the provider:
| Article | Topic | What it requires |
|---|---|---|
| Article 9 | Risk-management system | Continuous identification, analysis, and mitigation across the lifecycle |
| Article 10 | Data and data governance | Training, validation, and testing data quality and bias considerations |
| Article 11 + Annex IV | Technical documentation | Maintained current; specific Annex IV content list |
| Article 12 | Record-keeping (logging) | Automatic event logs sufficient for traceability and post-market monitoring |
| Article 13 | Transparency and provision of information to deployers | Instructions for use, system characteristics, intended purpose, limitations |
| Article 14 | Human oversight | Oversight measures designed into the system before market placement |
| Article 15 | Accuracy, robustness, and cybersecurity | Performance and resilience against errors, faults, attacks |
Go deeper: High-risk AI systems.
Conformity assessment and CE marking (at a glance)
Before placing a high-risk AI system on the market, providers must complete a conformity assessment under Article 43 (Annex I Section B products follow the relevant sectoral act):
| Route | What it means | When it applies |
|---|---|---|
| Annex VI internal control | Provider self-assesses against the Section 2 requirements | Annex III high-risk systems other than Annex III point 1 (biometrics); and Annex III point 1 systems where the provider has applied harmonised standards or common specifications |
| Annex VII notified body | Accredited third party audits the QMS and the technical documentation | Annex III point 1 (biometrics) systems where the provider has not applied harmonised standards or common specifications. For Annex III points 2–8, Article 43(2) requires Annex VI internal control — Annex VII is not a voluntary alternative. |
| Sectoral conformity (Annex I Section A) | Follow the conformity-assessment in the sectoral product legislation, integrating the AI Act requirements via Article 43(3) | Annex I Section A products that are safety components or are themselves such products; Section B products are not Article 43(3) cases and follow the relevant sectoral act |
A successful assessment leads to an EU declaration of conformity under Article 47 and CE marking under Article 48. Annex III systems must be registered in the EU database under Article 49 — with a narrow exception for Annex III point 2 (critical infrastructure) and specific carve-outs for law-enforcement / migration / border deployments where public-authority deployers register in a non-public section of the database.
Go deeper: Conformity assessment and CE marking.
General-purpose AI models (at a glance)
Chapter V (Articles 51–56) regulates general-purpose AI models separately from AI systems. Key triggers:
- Article 51 — a GPAI model is classified as having systemic risk under Article 51(1)(a) if the cumulative training compute exceeds 10²⁵ floating-point operations, or under Article 51(1)(b) if the Commission designates it (procedure in Article 52).
- Article 53 — provider obligations: technical documentation, downstream-provider documentation, copyright policy, training-data summary.
- Article 55 — additional obligations for systemic-risk GPAI: model evaluation, systemic-risk assessment and mitigation, serious-incident reporting to the AI Office, cybersecurity.
- Article 56 — Codes of Practice as a compliance tool until harmonised standards exist.
Go deeper: General-purpose AI models.
Post-market monitoring and serious incidents (at a glance)
- Article 72 — providers of high-risk AI systems establish and document a post-market monitoring plan proportionate to the system.
- Article 73 — providers report serious incidents to the market-surveillance authority of the Member State where the incident occurred. A serious incident is defined as one resulting in (a) death or serious harm to health, (b) serious and irreversible disruption of critical infrastructure, (c) infringement of fundamental rights under Union law, or (d) serious harm to property or environment. Article 73 sets event-specific deadlines (15 days as the general rule; 10 days where the incident resulted in a person's death; as soon as possible and not later than 2 days where it involved a widespread infringement or serious and irreversible disruption of critical infrastructure). These are distinct duties from Article 33 GDPR — different event types, different recipients, different deadlines.
Go deeper: Post-market monitoring.
Penalties and enforcement
Article 99 sets three administrative-fine tiers, calculated on the higher of an absolute amount or a percentage of total worldwide annual turnover of the preceding financial year (the lower of the two for SMEs and startups):
| Infringement | Fine ceiling |
|---|---|
| Article 5 prohibited practices | Up to €35 million or 7% of worldwide annual turnover |
| Most other operator obligations (high-risk, transparency, conformity assessment, etc.) | Up to €15 million or 3% |
| Supplying incorrect, incomplete or misleading information to notified bodies / competent authorities | Up to €7.5 million or 1% |
Article 101 sets a separate ceiling for GPAI model providers (up to €15 million or 3%). National-level penalties are set by Member States under Article 99(1) subject to the ceilings.
How Modulos operationalises EU AI Act compliance
Modulos models the Regulation through two framework templates:
- OFF-1 (EU AI Act, organisation-level) — 19 mapped requirements across the ORF-1…ORF-447 range; covers organisation-level obligations including QMS (Article 17), conformity-assessment governance (Article 43), serious-incident reporting workflow (Article 73), the Article 4a special-category bias-correction data basis (
ORF-447, added by the adopted Digital Omnibus on AI), and the GPAI organisation-level obligations. - MFF-1 (EU AI Act, application-level) — 57 mapped requirements across the MRF-1…MRF-413 range; covers per-AI-system technical and operational obligations including Articles 9–15 high-risk obligations, Article 27 FRIA, Article 50 transparency, post-market monitoring (Article 72), the Article 4a special-category bias-correction data basis (
MRF-413, added by the adopted Digital Omnibus on AI), and Chapter V GPAI obligations (MRF-120…MRF-131, scoped by theGPAIM,SRandGPAIMNonFOSStags).
Two first-class UI surfaces: project-level role tagging (Article 3 enums — Provider / Deployer / Importer / Distributor / Authorised Representative) and a project-level risk-classification setting (the four common industry labels — kept as a pragmatic filter, not a legal taxonomy). Everything else — FRIA, post-market monitoring plan, serious-incident reporting, CE marking and declaration, GPAI Codes of Practice, conformity-assessment route selection — is recorded as evidence linked to the relevant requirement, not as a dedicated workflow surface.
Framework mapping
Four layers, one reusable spine.
Frameworks
EU AI Act
ISO 42001
Requirements
Art. 9.1Risk management
Art. 10.2Data governance
6.1.1Risk assessment
Components
Risk identification
Impact analysis
Evidence
Risk register
Test results
Controls
The reusable spine
One control satisfies many requirements across many frameworks, and groups the components and evidence beneath them.
Risk assessment process
Data validation checks
Edge from any layer card crosses into the Controls spine — the same control may serve a regulatory article, a standards clause, a downstream component, and the evidence that closes it.
Go deeper: Operationalizing in Modulos.
Cross-framework mapping (preview)
| Concept | EU AI Act | Adjacent framework |
|---|---|---|
| Human oversight (design duty on provider) | Article 14 | NIST AI RMF MEASURE 2.6; ISO 42001 Annex A; ISO 9241 ergonomics analogy |
| Automated-decision data-subject right | (No direct provision) | Article 22 GDPR (data subject right; not the same as Article 14 EU AI Act) |
| Personal-data breach | (No direct provision) | Article 33 GDPR (personal-data breach within 72 hours; not the same as Article 73 EU AI Act serious incident) |
| Serious-incident reporting | Article 73 | NIS2 Article 23 incident notification (different threshold, different recipients) |
| Data governance for training/validation/test data | Article 10 | GDPR Articles 5, 6, 9; ISO 42001 Annex A controls |
| Risk-management system | Article 9 | NIST AI RMF Core Functions (Govern/Map/Measure/Manage); ISO 42001 Clauses 6–10; ISO 27001 Annex A |
| Quality-management system for providers | Article 17 | ISO 9001; ISO 42001 |
| Cybersecurity of high-risk AI systems | Article 15(5) | NIS2 Article 21; ISO 27001 Annex A |
Related pages
Prohibited practices and transparency
Article 5 prohibited practices + Article 50 transparency duties
High-risk AI systems
Article 6 + Annex I / III routing; Articles 8–15 obligations
Roles and responsibilities
Provider, deployer, importer, distributor, authorised representative; Article 25 accidental-provider
Conformity assessment and CE marking
Article 43 routes; Annex VI / VII; declaration; CE marking; EU database registration
General-purpose AI models
Chapter V (Articles 51–56); 10²⁵ FLOPs systemic-risk threshold; Codes of Practice
Post-market monitoring
Article 72 PMM plan; Article 73 serious-incident reporting (distinct from GDPR Art 33)
Operationalizing in Modulos
OFF-1 + MFF-1 rollout, scoping, evidence, exports
Commission guidance
Interpretive guidance on the AI-system definition, prohibited practices, and high-risk classification — soft law, not binding
EU AI Act vs GDPR
Side-by-side comparison of the two regimes
Source attribution
Regulation (EU) 2024/1689 of the European Parliament and of the Council of 13 June 2024 (the EU AI Act) is published in the Official Journal of the European Union L of 12 July 2024. Verbatim quotes on this page reflect the OJ-published 2024/1689 text. The Digital Omnibus on AI — approved by the European Parliament on 16 June 2026 (position P10_TA(2026)0198) and formally adopted by the Council on 29 June 2026, procedure 2025/0359(COD), based on Commission proposal COM(2025) 836 final of 19 November 2025 — is adopted but not yet in force; it enters into force on the third day after its publication in the Official Journal. Where it amends Regulation (EU) 2024/1689, the amended wording will govern from entry into force.
Disclaimer
This page is for general informational purposes and does not constitute legal advice.