Skip to content

EU AI Act

EU AI Act illustration

The EU AI Act — Regulation (EU) 2024/1689 — is the European Union's horizontal regulation on artificial intelligence. It governs AI systems in context (model + pipeline + human process + deployment environment) and general-purpose AI models as a separate regime, with directly applicable obligations across every Member State.

Quick decision

  • Just want to know if your AI system is in scope → if you place an AI system on the EU market, put one into service in the Union, or use the output in the Union, the Regulation applies under Article 2. Designate an authorized representative under Article 22 if you are a non-EU provider of a high-risk system.
  • Building or shipping a high-risk AI system → the substantive Articles 8–15 obligations bite. See High-risk AI systems.
  • Building or deploying a chatbot, emotion-recognition system, biometric categorizer, or anything that outputs deepfakes / synthetic media → Article 50 transparency duties apply independently of high-risk classification. See Prohibited practices and transparency.
  • Provider of a general-purpose AI model → Chapter V (Articles 51–56) applies at the model level. The 10²⁵ FLOPs training-compute threshold triggers the systemic-risk regime. See General-purpose AI models.
  • Worried the four-tier pyramid you read about everywhere is misleading → good. The Regulation does not use that framing. See Common misreadings of the AI Act below.

TL;DR

  • Regulation (EU) 2024/1689; OJ L of 12 July 2024; CELEX 32024R1689. Entered into force 1 August 2024.
  • Four obligation regimes can apply to the same system, independently and stacking: Article 5 prohibited practices; Article 6 + Annex I / III high-risk; Article 50 transparency on specific deployments; Chapter V GPAI at model level.
  • "Limited risk" and "minimal risk" are not defined categories in the Regulation. They are journalistic shorthand. See Common misreadings.
  • Article 4 AI literacy applies to all providers and deployers of any AI system — not just high-risk — from 2 February 2025. The four regimes above govern system-classification obligations; Article 4 sits on top of them.
  • Phased application: Article 5 prohibited practices from 2 February 2025; Chapter V GPAI from 2 August 2025. The Digital Omnibus on AI (Regulation (EU) 2026/1744, in force from 27 July 2026) defers the high-risk deadlines to 2 December 2027 (Annex III standalone) and 2 August 2028 (Annex I product-safety), replacing the original 2 August 2026 / 2 August 2027 dates; two new Article 5 prohibitions (NCII, CSAM) apply from 2 December 2026.
  • Penalties under Article 99 reach up to €35 million or 7% of worldwide annual turnover for Article 5 infringements; up to €15 million or 3% for most other obligations on operators.
  • Modulos operationalizes the AI Act through the OFF-1 (organization) and MFF-1 (AI application) framework templates; GPAI is folded into MFF-1 via the scoping questionnaire, not a separate template.

Digital Omnibus on AI

Status: Regulation (EU) 2026/1744 — in force from 27 July 2026

The Digital Omnibus on AI is Regulation (EU) 2026/1744 of the European Parliament and of the Council of 8 July 2026, published in the Official Journal L of 24 July 2026 (EUR-Lex CELEX 32026R1744). It amends Regulations (EU) 2024/1689 (AI Act), (EU) 2018/1139 and (EU) 2023/1230, and entered into force on 27 July 2026 (the third day following its OJ publication). The European Parliament approved the text on 16 June 2026 (legislative resolution P10_TA(2026)0198) and the Council adopted it on 29 June 2026, closing procedure 2025/0359(COD) (Commission proposal COM(2025) 836 of 19 November 2025).

These amendments supersede the original Regulation (EU) 2024/1689 dates where they amend them. The substantive effects for the AI Act are:

  • High-risk application dates move to fixed new deadlines — standalone Annex III obligations (Article 6(2)) move from 2 August 2026 to 2 December 2027; product-safety Annex I obligations (Article 6(1)) move from 2 August 2027 to 2 August 2028 (Article 113, as amended). Fixed application dates replace the Commission's original readiness-decision model.
  • Two new prohibited practices — Article 5(1) gains point (ba) (AI generating non-consensual intimate imagery) and point (bb) (AI generating child sexual abuse material or performances within the meaning of Directive 2011/93/EU). Both apply from 2 December 2026.
  • The safety-component boundary is narrowed — amended Article 3(14) clarifies the safety-function test (intended purpose of preventing or mitigating health-and-safety risks) while keeping the failure-or-malfunctioning limb; new Articles 6(1a)-(1c) exclude AI used solely for non-safety-related aspects of user assistance, performance optimization, service efficiency, automation or convenience or quality control, pull failure-endangering systems back in, and disregard third-party assessments required solely for non-health-and-safety risks.
  • Legacy-system grace period re-keyed, public-authority deadline confirmed — replaced Article 111(2) ties the grace period for high-risk systems already on the market to the new Chapter III application dates (at the level of the type and model per recital 39, and without prejudice to Article 5); providers and deployers of high-risk AI intended for use by public authorities must comply by 2 August 2030.
  • Article 50(2) synthetic-content marking — four-month grace — providers of synthetic-content AI systems already placed on the EU market before 2 August 2026 have until 2 December 2026 to meet the Article 50(2) provider-side machine-readable marking duty (new Article 111(4)). Deployer-side Article 50(4) disclosure is not extended.
  • Annex III non-high-risk registration retained but simplified — providers that determine an Annex III use case is not high-risk still register it in the EU database, with reduced content requirements (Annex VIII, Section B points 7 and 9 deleted).
  • National regulatory sandboxes — deadline 2 August 2027 — each Member State must have at least one operational AI regulatory sandbox by 2 August 2027 (Article 57(1)), a one-year shift; the AI Office may also run a Union-level sandbox.
  • Bias-correction data basis kept and extended — a new Article 4a retains the strict-necessity legal basis to process special-category personal data for bias detection and correction, and extends it to deployers and to providers/deployers of other AI systems and models.
  • AI literacy obligation recalibrated — Article 4 requires providers and deployers to "take measures to support the development of AI literacy", with no obligation to guarantee any specific level for any individual.
  • Simplified compliance for SMEs and Small Mid-Caps (SMCs) — a new SMC definition (Commission Recommendation (EU) 2025/1099) brings simplified technical documentation (Article 11) and proportionate quality-management obligations (Article 17) to SMEs, start-ups and SMCs, extends the lower-of fine cap to SMCs (Article 99(6a)), and adds proportionality and viability considerations.
  • AI Office given exclusive competence and enforcement powers — the AI Office exclusively supervises AI systems built on general-purpose AI models where the model and system come from the same provider or the same undertaking (carve-outs for Annex I products, Annex III point 2 critical infrastructure, law enforcement, border management, Annex III point 8 administration of justice and financial institutions), and AI that constitutes or is integrated into a very large online platform or search engine; new Articles 75a–75d give it full market-surveillance, fining and penalty powers; under new Article 75(1e) the AI Office is also responsible for the Article 43 third-party conformity assessments of those systems, with tests entrusted to notified bodies on the Commission's behalf and fees levied on the provider.
  • Sectoral overlaps can be resolved through delegated acts — where sectoral law in Section A of Annex I provides an equivalent or higher level of protection, the Commission may limit the application of the Articles 9-15 and 17-25 requirements via delegated acts, provided the overall level of protection is not reduced (new Article 2(13); by 2 August 2027).
  • Value-chain duties made expressly fineable, notified-body transition fixed — breaches of the Article 25(2) and 25(4) provider and operator duties are added to the Article 99(4) administrative-fine tier (new point (da)); notified bodies already notified under Section A Annex I law must apply for AI Act designation by 28 January 2028 (Article 43(3)).
  • Machinery moved to the sectoral track — the Omnibus deletes the Machinery Directive 2006/42/EC from Annex I Section A and adds the Machinery Regulation (EU) 2023/1230 to Annex I Section B (point 21); the Commission will add health-and-safety requirements for high-risk AI in machinery by delegated act, applicable by 2 August 2028.

For Modulos' public analysis, see modulos.ai/eu-ai-act/.

Primary sources

Verbatim quotes on this page reflect the OJ-published 2024/1689 text; where the Digital Omnibus (Regulation (EU) 2026/1744) amends a provision, the amended wording governs.

Article 1 — subject matter

The purpose of this Regulation is to improve the functioning of the internal market and promote the uptake of human-centric and trustworthy artificial intelligence (AI), while ensuring a high level of protection of health, safety, fundamental rights enshrined in the Charter, including democracy, the rule of law and environmental protection, against the harmful effects of AI systems in the Union and supporting innovation.

— Article 1(1), Regulation (EU) 2024/1689

The Regulation is built on Articles 16 and 114 TFEU (data protection + internal market) with a fundamental-rights overlay. The result is product-safety mechanics (classification, conformity assessment, CE marking, post-market monitoring, market surveillance) anchored to a fundamental-rights protective purpose.

Article 3(1) — what counts as an 'AI system'

‘AI system’ means a machine-based system that is designed to operate with varying levels of autonomy and that may exhibit adaptiveness after deployment, and that, for explicit or implicit objectives, infers, from the input it receives, how to generate outputs such as predictions, content, recommendations, or decisions that can influence physical or virtual environments;

— Article 3(1), Regulation (EU) 2024/1689

This definition is system-level, not model-level. Compliance work includes the model, the surrounding pipeline, the human process, and the environment where outputs influence decisions.

If you only govern "the model", you will miss what auditors and regulators actually care about: data governance, deployment constraints, monitoring, human oversight, and traceability.

Background note (external): A taxonomy of AI systems and models in the EU AI Act.

Go deeper: the Commission has issued interpretive guidance on the Article 3(1) definition (Communication C(2025) 5053 final, 29 July 2025) decomposing the definition into seven elements and identifying four categories of systems that fall outside it.

Four obligation regimes (not a 'risk pyramid')

The Regulation defines four independent gates that can apply to the same AI system. Each gate has its own trigger; the same system can fire several at once and the obligations apply in parallel.

Important: these regimes stack, they don't tier

The Regulation does not describe a hierarchy. A high-risk AI system can also be subject to Article 50 transparency duties. A GPAI model can be deployed inside a high-risk AI system. "Limited risk" and "minimal risk" are not defined categories in the Regulation — see Common misreadings.

Classification flow

  1. Define the AI system and its intended purpose under Article 3(1).
  2. Article 5 prohibited? If the use case falls within Article 5(1)(a)–(h), the system cannot be deployed in the EU — except where a statutory exception applies (notably the 5(1)(h)(i)–(iii) real-time RBI law-enforcement objectives under the 5(2)–(7) authorization regime). Outside those narrow exceptions, the route is redesign, scope-out, or stop.
  3. Article 6 high-risk? Article 6(1) covers AI systems that are themselves products, or safety components of products, covered by the Annex I Union harmonization legislation (medical devices, machinery, vehicles, etc.) and required to undergo a third-party conformity assessment under that legislation. Article 6(2) covers Annex III standalone use cases (biometrics, critical infrastructure, education, employment, essential services, law enforcement, migration / border, justice / democratic processes). Articles 8–15 obligations apply across the lifecycle (for Annex I Section B products they are integrated through the sectoral act).
  4. Article 50 transparency applies independently to chatbots, emotion recognition, biometric categorization, deepfakes, and AI-generated content — whether or not the system is high-risk.
  5. Built on a GPAI model? The upstream model provider has obligations under Articles 53–55 (transparency, copyright policy, downstream documentation; systemic-risk obligations if above 10²⁵ FLOPs). System-level obligations on the deployer are separate.

Go deeper: High-risk AI systems · Prohibited practices and transparency · General-purpose AI models.

Common misreadings of the AI Act

Public commentary about the Regulation is uneven. The frequent mistakes — most of them inherited from pre-final-text drafts — are worth calling out explicitly. Each is anchored to the Article that proves it wrong.

  • "The AI Act is a four-tier risk pyramid (unacceptable / high / limited / minimal)." The Regulation does not use the word pyramid anywhere, and "limited" and "minimal" are not defined categories. Articles 5, 6, and 50 define three separate operative regimes that can stack on the same system; Chapter V (Articles 51–56) is a fourth, model-level regime that doesn't fit the visual hierarchy at all.
  • "Limited risk = Article 50 transparency tier." Article 50 imposes transparency duties on specific deployments (chatbots, emotion recognition, biometric categorization, deepfakes, AI-generated content). The system carrying those duties may also be high-risk. "Limited risk" is not a tier — it is shorthand for "Article 50 may apply".
  • "Minimal risk systems must follow voluntary codes." The Regulation imposes no system-classification obligations outside the four regimes above. But Article 4 (AI literacy) applies to providers and deployers of any AI system — not only high-risk — from 2 February 2025. Voluntary codes of conduct under Article 95 are voluntary. The residual is "no Articles 5/6/50/Chapter V obligations", not "no AI Act obligations at all".
  • "Prohibited = top of the pyramid; just the strictest tier of compliance." Article 5 prohibitions are bans with narrow statutory exceptions (most notably the conditional 5(1)(h) real-time RBI law-enforcement regime under 5(2)–(7)). There is no "compliance" route outside those exceptions — the operative duty is don't place on the market, don't put into service, don't use. Compliance-style framing for prohibited practices misleads.
  • "Generative AI / foundation models are automatically high-risk." General-purpose AI models are regulated under Chapter V (Articles 51–56) at the model level, with their own provider obligations and systemic-risk threshold (10²⁵ FLOPs). High-risk classification under Article 6 is a system-level question driven by intended purpose; a GenAI model becomes part of a high-risk system only when integrated into one whose use case falls under Annex III or Annex I.
  • "High-risk is one bucket." Article 6(1) covers AI systems that are safety components of products covered by Annex I sectoral law (medical devices, machinery, vehicles, …). Article 6(2) covers Annex III standalone use cases. The two routes have different conformity-assessment paths (Annex I Section A uses the Article 43(3) sectoral integration route; Section B follows the relevant sectoral regime where AI requirements are integrated; Annex III generally uses Annex VI internal control unless the system performs biometric identification).
  • "Article 22 GDPR and Article 14 EU AI Act are the same human-oversight obligation." They are not. Article 14 is a design duty on providers of high-risk AI systems (oversight measures built into the system). Article 22 GDPR is a data-subject right against solely-automated decisions producing legal or similarly significant effects. The duties have different addressees, scopes, and remedies.
  • "Article 33 GDPR and Article 73 EU AI Act are the same 72-hour breach duty." They are not. Article 33 GDPR governs notification of personal-data breaches to supervisory authorities. Article 73 EU AI Act governs reporting of serious incidents (death, serious harm to health, serious and irreversible disruption of critical infrastructure, infringement of fundamental rights) by providers of high-risk AI systems to market-surveillance authorities. Reporting deadlines differ and the events are different.

How this lands in Modulos

The active project setting is Use Case (High Risk / Limited Risk / Transparency), a deployment-context filter that scopes the active requirements set. It is not a legal high-risk classification. The Article 6 + Annex I / III rationale on the MFF-1 classification requirement is the legal answer. See Operationalizing in Modulos for the full settings surface.

Timeline

1 August 2024
Regulation (EU) 2024/1689 enters into force
2 February 2025
Original Article 5(1)(a)-(h) prohibited practices apply
2 August 2025
Chapter V GPAI provider obligations apply
2 December 2026
New Article 5 prohibitions (NCII, CSAM) apply, and legacy synthetic-content systems must meet Article 50(2) marking, under the Digital Omnibus (Regulation (EU) 2026/1744)
2 December 2027
Annex III standalone high-risk obligations apply on 2 December 2027 under the Digital Omnibus (Regulation (EU) 2026/1744) (deferred from 2 August 2026)
2 August 2028
Annex I product-safety high-risk obligations apply on 2 August 2028 under the Digital Omnibus (Regulation (EU) 2026/1744) (deferred from 2 August 2027)

Roles and responsibilities (at a glance)

The Regulation assigns obligations by legal role (Article 3 definitions). These are distinct from Modulos project roles (Owner, Editor, Viewer).

  • Provider (Article 3(3)): develops or has developed an AI system or general-purpose AI model and places it on the EU market or puts it into service under its own name or trademark. Provider duties on high-risk AI systems sit in Article 16; provider duties on GPAI models sit in Article 53 (and additional duties for systemic-risk GPAI in Article 55).
  • Deployer (Article 3(4); high-risk-system duties in Article 26): uses an AI system under its own authority (other than for personal non-professional activity).
  • Importer (Article 3(6); duties in Article 23) and distributor (Article 3(7); duties in Article 24): make systems available in the EU supply chain.
  • Authorized representative (Article 3(5)): represents non-EU providers in the Union. For high-risk AI systems the duties sit in Article 22; for GPAI model providers they sit in Article 54.

Article 25 — accidental provider

A deployer, importer, or distributor becomes a provider under Article 25 if it (a) puts its own name or trademark on a high-risk AI system, (b) makes a substantial modification to a high-risk AI system on the market, or (c) modifies the intended purpose of a non-high-risk AI system so that it becomes high-risk. The original provider's obligations transfer.

Go deeper: Roles and responsibilities.

High-risk obligations (at a glance)

For high-risk AI systems, Articles 8–15 impose continuous lifecycle obligations on the provider:

ArticleTopicWhat it requires
Article 9Risk-management systemContinuous identification, analysis, and mitigation across the lifecycle
Article 10Data and data governanceTraining, validation, and testing data quality and bias considerations
Article 11 + Annex IVTechnical documentationMaintained current; specific Annex IV content list
Article 12Record-keeping (logging)Automatic event logs sufficient for traceability and post-market monitoring
Article 13Transparency and provision of information to deployersInstructions for use, system characteristics, intended purpose, limitations
Article 14Human oversightOversight measures designed into the system before market placement
Article 15Accuracy, robustness, and cybersecurityPerformance and resilience against errors, faults, attacks

Go deeper: High-risk AI systems.

Conformity assessment and CE marking (at a glance)

Before placing a high-risk AI system on the market, providers must complete a conformity assessment under Article 43 (Annex I Section B products follow the relevant sectoral act):

RouteWhat it meansWhen it applies
Annex VI internal controlProvider self-assesses against the Section 2 requirementsAnnex III high-risk systems other than Annex III point 1 (biometrics); and Annex III point 1 systems where the provider has applied harmonized standards or common specifications
Annex VII notified bodyAccredited third party audits the QMS and the technical documentationAnnex III point 1 (biometrics) systems where the provider has not applied harmonized standards or common specifications. For Annex III points 2–8, Article 43(2) requires Annex VI internal control — Annex VII is not a voluntary alternative.
Sectoral conformity (Annex I Section A)Follow the conformity-assessment in the sectoral product legislation, integrating the AI Act requirements via Article 43(3)Annex I Section A products that are safety components or are themselves such products; Section B products are not Article 43(3) cases and follow the relevant sectoral act

A successful assessment leads to an EU declaration of conformity under Article 47 and CE marking under Article 48. Annex III systems must be registered in the EU database under Article 49 — with a narrow exception for Annex III point 2 (critical infrastructure) and specific carve-outs for law-enforcement / migration / border deployments where public-authority deployers register in a non-public section of the database.

Go deeper: Conformity assessment and CE marking.

General-purpose AI models (at a glance)

Chapter V (Articles 51–56) regulates general-purpose AI models separately from AI systems. Key triggers:

  • Article 51 — a GPAI model is classified as having systemic risk under Article 51(1)(a) if the cumulative training compute exceeds 10²⁵ floating-point operations, or under Article 51(1)(b) if the Commission designates it (procedure in Article 52).
  • Article 53 — provider obligations: technical documentation, downstream-provider documentation, copyright policy, training-data summary.
  • Article 55 — additional obligations for systemic-risk GPAI: model evaluation, systemic-risk assessment and mitigation, serious-incident reporting to the AI Office, cybersecurity.
  • Article 56 — Codes of Practice as a compliance tool until harmonized standards exist.

Go deeper: General-purpose AI models.

Post-market monitoring and serious incidents (at a glance)

  • Article 72 — providers of high-risk AI systems establish and document a post-market monitoring plan proportionate to the system.
  • Article 73 — providers report serious incidents to the market-surveillance authority of the Member State where the incident occurred. A serious incident is defined as one resulting in (a) death or serious harm to health, (b) serious and irreversible disruption of critical infrastructure, (c) infringement of fundamental rights under Union law, or (d) serious harm to property or environment. Article 73 sets event-specific deadlines (15 days as the general rule; 10 days where the incident resulted in a person's death; as soon as possible and not later than 2 days where it involved a widespread infringement or serious and irreversible disruption of critical infrastructure). These are distinct duties from Article 33 GDPR — different event types, different recipients, different deadlines.

Go deeper: Post-market monitoring.

Penalties and enforcement

Article 99 sets three administrative-fine tiers, calculated on the higher of an absolute amount or a percentage of total worldwide annual turnover of the preceding financial year (the lower of the two for SMEs and startups):

InfringementFine ceiling
Article 5 prohibited practicesUp to €35 million or 7% of worldwide annual turnover
Most other operator obligations (high-risk, transparency, conformity assessment, etc.)Up to €15 million or 3%
Supplying incorrect, incomplete or misleading information to notified bodies / competent authoritiesUp to €7.5 million or 1%

Article 101 sets a separate ceiling for GPAI model providers (up to €15 million or 3%). National-level penalties are set by Member States under Article 99(1) subject to the ceilings.

How Modulos operationalizes EU AI Act compliance

Modulos models the Regulation through two framework templates:

  • OFF-1 (EU AI Act, organization-level) — 19 mapped requirements across the ORF-1…ORF-447 range; covers organization-level obligations including QMS (Article 17), conformity-assessment governance (Article 43), serious-incident reporting workflow (Article 73), the Article 4a special-category bias-correction data basis (ORF-447, added by the Digital Omnibus on AI, Regulation (EU) 2026/1744), and the GPAI organization-level obligations.
  • MFF-1 (EU AI Act, application-level) — 57 mapped requirements across the MRF-1…MRF-413 range; covers per-AI-system technical and operational obligations including Articles 9–15 high-risk obligations, Article 27 FRIA, Article 50 transparency, post-market monitoring (Article 72), the Article 4a special-category bias-correction data basis (MRF-413, added by the Digital Omnibus on AI, Regulation (EU) 2026/1744), and Chapter V GPAI obligations (MRF-120…MRF-131, scoped by the GPAIM, SR and GPAIMNonFOSS tags).

Two first-class UI surfaces: project-level role tagging (Article 3 enums — Provider / Deployer / Importer / Distributor / Authorized Representative) and a project-level risk-classification setting (the four common industry labels — kept as a pragmatic filter, not a legal taxonomy). Everything else — FRIA, post-market monitoring plan, serious-incident reporting, CE marking and declaration, GPAI Codes of Practice, conformity-assessment route selection — is recorded as evidence linked to the relevant requirement, not as a dedicated workflow surface.

Go deeper: Operationalizing in Modulos.

Cross-framework mapping (preview)

ConceptEU AI ActAdjacent framework
Human oversight (design duty on provider)Article 14NIST AI RMF MEASURE 2.6; ISO 42001 Annex A; ISO 9241 ergonomics analogy
Automated-decision data-subject right(No direct provision)Article 22 GDPR (data subject right; not the same as Article 14 EU AI Act)
Personal-data breach(No direct provision)Article 33 GDPR (personal-data breach within 72 hours; not the same as Article 73 EU AI Act serious incident)
Serious-incident reportingArticle 73NIS2 Article 23 incident notification (different threshold, different recipients)
Data governance for training/validation/test dataArticle 10GDPR Articles 5, 6, 9; ISO 42001 Annex A controls
Risk-management systemArticle 9NIST AI RMF Core Functions (Govern/Map/Measure/Manage); ISO 42001 Clauses 6–10; ISO 27001 Annex A
Quality-management system for providersArticle 17ISO 9001; ISO 42001
Cybersecurity of high-risk AI systemsArticle 15(5)NIS2 Article 21; ISO 27001 Annex A

Source attribution

Regulation (EU) 2024/1689 of the European Parliament and of the Council of 13 June 2024 (the EU AI Act) is published in the Official Journal of the European Union L of 12 July 2024. Verbatim quotes on this page reflect the OJ-published 2024/1689 text. The Digital Omnibus on AI is Regulation (EU) 2026/1744 of 8 July 2026, published in the Official Journal L of 24 July 2026 (CELEX 32026R1744), procedure 2025/0359(COD), based on Commission proposal COM(2025) 836 final of 19 November 2025; it entered into force on 27 July 2026. Where it amends Regulation (EU) 2024/1689, the amended wording governs.

Disclaimer

This page is for general informational purposes and does not constitute legal advice.