The EU AI Act, explained end to end
The EU AI Act is the world’s first comprehensive law on artificial intelligence. It entered into force on 1 August 2024 and does not treat all AI the same: it sorts systems into prohibited, high-risk, limited-risk and minimal tiers, then attaches obligations proportionate to the risk each poses to health, safety and fundamental rights.
It applies extraterritorially. If your system is placed on the EU market, put into service in the EU, or its output is used in the EU, you are in scope — wherever your company sits. And duties are assigned by operator role, not by industry: the same system can make one company a provider and another a deployer, with completely different obligations.
Start here
There are three useful ways into the Act. Pick the one that matches the question you actually have.
“Which duties are mine?”
Start with your operator role. Provider, deployer, importer, distributor and GPAI provider each carry a different obligation set, and you can hold more than one.
5 roles compared“Is my system high-risk?”
Most of the Act’s weight lands on high-risk AI, and Annex III is the list that defines it. Check your use case against the eight areas the Act names.
8 Annex III areas“What does Article N say?”
A plain-English reference to the articles teams actually cite — what each requires, who it binds, and the points that matter in practice.
15 articles explainedThe deadlines that are actually in force
The 2026 Digital Omnibus on AI moved the high-risk dates back and left the transparency date alone. These are the amended dates.
- 2 Feb 2025Prohibitions & AI literacyIn force
Article 5 bans took effect, alongside the Article 4 duty to give staff sufficient AI literacy.
- 2 Aug 2025GPAI model providersIn force
Articles 53–55 apply: technical documentation, a training-data summary and a copyright policy.
- 2 Aug 2026Transparency (Article 50)In force
Chatbots must say they are AI, and synthetic audio, image, video and text must be marked machine-readably. Deepfakes need a visible label.
- 2 Dec 2026Content-marking transition endsUpcoming
Generative systems already on the market before 2 August 2026 must have machine-readable marking in place by this date.
- 2 Dec 2027High-risk — Annex IIIUpcoming
Articles 9–15 become enforceable for Annex III systems. Moved from 2 Aug 2026 by the 2026 Digital Omnibus — a fixed date, with no standards-availability escape hatch.
- 2 Aug 2028High-risk — Annex I productsUpcoming
High-risk AI embedded in regulated products (medical devices, machinery, toys, vehicles) becomes enforceable. Moved from 2 Aug 2027 by the Digital Omnibus.
Track every change as it lands on the regulation radar or in the deadline tracker.
Obligations by operator role
The Act assigns duties by role, defined in Article 3. Find yours — and note that rebranding or substantially modifying a high-risk system (Article 25) turns a deployer, importer or distributor into a provider.
Provider
If you build or brand an AI system, you're a provider under the EU AI Act. See every provider obligation — Art. 9–21, conformity assessment, CE marking — in plain English.
15 obligationsDeployer
Using an AI tool built by someone else? You're a deployer under the EU AI Act. Learn your Article 26 duties — human oversight, monitoring, FRIA — and how to comply.
10 obligationsImporter
Placing a non-EU provider's AI system on the EU market? You're an importer under the EU AI Act. See your Article 23 verification duties before you can sell.
8 obligationsDistributor
Reselling or making an AI system available in the EU? You're a distributor under the EU AI Act. Learn your Article 24 checks and when duties escalate to provider level.
7 obligationsGPAI model provider
Building a foundation model or LLM? You're a GPAI provider under the EU AI Act. See Article 53–55 duties: technical docs, copyright policy, training-data summary, systemic risk.
9 obligationsCompare all roles side by sideIncludes the 10-second test for working out which one you are.High-risk use cases (Annex III)
If your system does one of these things, it is almost certainly high-risk — which pulls in the full Article 9–15 programme by 2 December 2027.
Biometrics
Remote biometric identification systems · Biometric categorisation by sensitive attributes · Emotion-recognition systems
Annex III(2)Critical infrastructure
Safety components in critical digital infrastructure · Road-traffic management · Supply of water, gas, heating and electricity
Annex III(3)Education
Admission and assignment to institutions · Evaluating learning outcomes · Assessing the appropriate level of education
Annex III(4)Employment & HR
Recruitment and selection (ad targeting, filtering, evaluating candidates) · Decisions on terms, promotion and termination · Task allocation based on behaviour or traits
Annex III(5)Credit & essential services
Eligibility for public assistance benefits and services · Creditworthiness and credit scoring (except fraud detection) · Risk assessment and pricing in life and health insurance
Annex III(6)Law enforcement
Assessing the risk of a person becoming a crime victim · Polygraphs and similar tools · Evaluating the reliability of evidence
Annex III(7)Migration & borders
Polygraphs and similar tools · Assessing security, irregular-migration and health risks · Examining applications for asylum, visa and residence permits
Annex III(8)Justice & democracy
Assisting judicial authorities in researching and interpreting facts and the law · Applying the law to a concrete set of facts · Influencing the outcome of elections or referenda, or voting behaviour
Article by article
The provisions teams cite most often, each in plain English with the obligation, the operators it binds and the penalty band it sits in.
The Act in your sector
The Act does not regulate industries — it regulates uses. But the uses cluster by sector, so these pages start from the AI you probably already run and work back to the obligations it triggers.
Recruitment & Hiring
CV / resume screening and filtering · Candidate ranking and shortlisting · Automated video or game-based assessment
6 obligations mappedHR & Workforce
CV parsing and automated candidate shortlisting · Interview scoring and video-analysis assessment · Performance evaluation and promotion ranking
6 obligations mappedFintech & Banking
Credit scoring and creditworthiness assessment · Automated loan and mortgage underwriting · Transaction fraud detection
6 obligations mappedHealthcare
AI-assisted diagnostic imaging (radiology, pathology) · Clinical decision-support and treatment recommendation · Emergency triage and patient prioritisation
6 obligations mappedSaaS & Software
In-app customer-support chatbots and assistants · AI content and copy generation features · Automated summarisation and data extraction
6 obligations mappedInsurance
Automated risk assessment for life insurance · AI-driven premium pricing for health cover · Underwriting eligibility and acceptance decisions
6 obligations mappedEducation & EdTech
Automated admissions and enrolment decisions · AI exam scoring and essay grading · Remote proctoring and cheating detection
6 obligations mappedMarketing & AdTech
Generative ad copy and creative production · AI-generated product and campaign imagery · Conversational marketing and sales chatbots
6 obligations mappedLegal & Law Firms
Contract review and clause extraction · Legal research and case-law analysis · E-discovery and document review
6 obligations mappedRetail & E-commerce
Product recommendation and personalisation engines · Customer-service and shopping chatbots · Demand forecasting and inventory optimisation
6 obligations mappedManufacturing & Industry
AI safety components in machinery and robotics · Predictive maintenance of equipment · Computer-vision quality inspection
6 obligations mappedPublic Sector & Government
Automated benefit and welfare eligibility assessment · Fraud and error detection in public programmes · Predictive and investigative policing support
6 obligations mappedBanking
Consumer credit scoring and creditworthiness assessment · Automated loan and mortgage underwriting · Transaction fraud detection
6 obligations mappedTelecommunications
Network traffic optimisation and management · Predictive maintenance of network equipment · Customer-service and support chatbots
6 obligations mappedAutomotive
Advanced driver-assistance systems (ADAS) · Perception and object-detection for autonomous driving · Automated emergency braking and safety functions
6 obligations mappedEnergy & Utilities
Grid balancing and load management safety systems · Fault detection and outage prediction · Predictive maintenance of generation and network assets
6 obligations mappedLogistics & Transport
Route optimisation and ETA prediction · Demand and capacity forecasting · Warehouse robotics and pick-path optimisation
6 obligations mappedReal Estate & PropTech
Automated valuation models (AVMs) for property pricing · Property search and recommendation ranking · Lead qualification and sales chatbots
6 obligations mappedIn-depth guides
EU AI Act Compliance: The Complete Guide (2026)
A practical guide to EU AI Act compliance: risk tiers, who's in scope, obligations, deadlines and penalties — with the steps to get audit-ready.
11 min readHigh-Risk AI Systems & Annex III: The Full Guide
Learn what makes an AI system high-risk under the EU AI Act — the full Annex III list, Article 6 safety components, the exemption, and your next steps.
9 min readFundamentalsProhibited AI Practices Under Article 5 Explained
Article 5 of the EU AI Act bans certain AI practices outright — banned since 2 Feb 2025. See the full prohibited list, the €35M penalties, and how to check.
8 min readObligationsAnnex IV Technical Documentation: A Practical Guide
The Annex IV technical file is mandatory for high-risk AI under Article 11. Learn exactly what it must contain and how to produce a compliant document.
9 min readObligationsGPAI Obligations Under the EU AI Act: Provider Duties
What general-purpose AI (GPAI) model providers must do under the EU AI Act since 2 August 2025: documentation, copyright policy, training-data summary and systemic-risk duties.
9 min readObligationsAI Literacy Under Article 4 of the EU AI Act
Article 4 of the EU AI Act requires providers and deployers to ensure sufficient AI literacy among staff since 2 February 2025. What it means, who it covers and how to evidence it.
7 min readDeadlinesEU AI Act Deadlines: The Full Compliance Timeline
A clear, scannable timeline of every EU AI Act deadline — from prohibited practices in February 2025, through the Article 50 transparency duties already in force, to the final Annex I date in August 2028.
8 min readFundamentalsEU AI Act Penalties & Fines: The 2026 Guide to the Tiers
How EU AI Act penalties work: the three fine tiers (up to €35M or 7% turnover), who can be fined, SME caps, and the real cost of non-compliance.
8 min readComparisonsEU AI Act vs GDPR: Key Differences, Overlaps & Compliance
EU AI Act vs GDPR compared: personal data vs AI risk, where the two overlap on automated decisions and impact assessments, and why many firms need both.
8 min readFundamentalsDoes the EU AI Act Apply to US Companies? (2026)
Yes — the EU AI Act is extraterritorial. If your AI system or its output is used in the EU, you're in scope even as a US company. Here's exactly when and what to do.
8 min readObligationsEU AI Act Compliance Checklist (2026)
A practical, step-by-step EU AI Act compliance checklist: inventory, classify, assign roles, meet obligations, generate documentation and track deadlines.
7 min readObligationsEU AI Act Conformity Assessment Explained (Article 43)
What is a conformity assessment under the EU AI Act? Learn the two routes (internal control vs notified body), when each applies, and the CE-marking steps that follow.
7 min readFundamentalsEU AI Act for Startups & SMEs: What You Actually Need to Do
The EU AI Act applies to startups and SMEs too — but with proportionate measures. Learn what small companies must do, the relief available, and where to focus first.
6 min readDeadlinesWhat Changes on 2 August 2026 Under the EU AI Act
Since 2 Aug 2026 the Article 50 transparency duties and GPAI enforcement powers have applied — but high-risk moved to Dec 2027. What actually landed, and what to do now.
8 min readObligationsAI Watermarking & Content Marking Under the EU AI Act
Article 50(2) requires machine-readable marking of AI-generated content from 2 Aug 2026. Who it covers, the Dec 2026 transition, and how to implement it.
7 min readFree tools
Reading about the Act only gets you so far. These answer the question for your own systems, and none of them need an account.
Free AI Act classifier
Answer a short set of questions and get a deterministic risk classification per system — no sign-up.
Article 50 readiness checker
Test your chatbot disclosures, deepfake labels and machine-readable marking against the obligation that is already live.
Deadline tracker
Every milestone from 2 February 2025 to 2 August 2028, with the post-Omnibus dates.
Penalty calculator
See which Article 99 band a breach falls in and what the higher-of-two maximum works out to for your turnover.
Watermark & provenance checker
Inspect a file for the provenance metadata Article 50(2) expects on AI-generated content.
Enforcement tracker
What national authorities and the AI Office have actually done, as it happens.
Narrated example audits
Watch fictional companies get audited feature by feature, so you can see what the Act means in practice.
Classification methodology
How the classifier reaches its answer, article by article — the reasoning is open, not a black box.
The vocabulary
The Act is precise about its terms, and the definitions are load-bearing — “placing on the market”, “substantial modification” and “deployer” all decide who owes what. Each term below links to its definition and the article it comes from.
Core concepts
Risk tiers
Operator roles
Obligations
Documents & conformity
Read it in your language
The Regulation is published in every official EU language, so the defined terms have canonical translations. These are complete pillar guides, not machine translations of this page.
Frequently asked questions
What is the EU AI Act?
The EU AI Act (Regulation (EU) 2024/1689) is the world's first comprehensive law on artificial intelligence. It entered into force on 1 August 2024 and sorts AI systems into risk tiers — prohibited, high-risk, limited-risk and minimal — attaching obligations proportionate to the risk each poses to health, safety and fundamental rights.
Who does the EU AI Act apply to?
It applies extraterritorially. If your AI system is placed on the EU market, put into service in the EU, or its output is used in the EU, you are in scope regardless of where your company is established. Duties are assigned by operator role — provider, deployer, importer, distributor or GPAI model provider — not by industry or company size.
When do the EU AI Act obligations apply?
In stages. Article 5 prohibitions and the Article 4 AI-literacy duty have applied since 2 February 2025; GPAI obligations since 2 August 2025; Article 50 transparency since 2 August 2026. After the 2026 Digital Omnibus, Annex III high-risk obligations apply from 2 December 2027 and Annex I product-safety high-risk obligations from 2 August 2028.
How do I know whether my AI system is high-risk?
A system is high-risk if it is a safety component of a product covered by Annex I, or if it falls under one of the eight Annex III use-case areas — biometrics, critical infrastructure, education, employment, essential services and credit scoring, law enforcement, migration and border control, and administration of justice. Annex III systems can still fall out of scope through the Article 6(3) filter conditions.
What are the penalties under the EU AI Act?
Article 99 sets three bands, each the higher of a fixed amount or a share of worldwide annual turnover: up to €35 million or 7% for breaching the Article 5 prohibitions, up to €15 million or 3% for most other obligations, and up to €7.5 million or 1% for supplying incorrect, incomplete or misleading information.
What is the difference between a provider and a deployer?
A provider develops an AI system, or has one developed, and places it on the market or puts it into service under its own name or trademark. A deployer uses an AI system under its own authority in a professional capacity. The obligation sets differ substantially, and under Article 25 a deployer, importer or distributor becomes a provider if it rebrands a high-risk system or substantially modifies it.
The free checker classifies each of your systems deterministically and shows the articles behind every answer. No sign-up.
This page summarises Regulation (EU) 2024/1689 as amended by the 2026 Digital Omnibus on AI. It is general information, not legal advice.