Operational guidance, not legal advice. This page distills named public sources (regulator guidance and industry practice). It is not a legal determination, not a notification decision, and not a substitute for your counsel, insurer, or a retained DFIR firm. Verify applicability and current deadlines for your facts and jurisdiction.

What cybersecurity does the EU AI Act require of AI systems?

Last verified

Articles 15 and 55 of Regulation (EU) 2024/1689 are distinct cybersecurity duties: high-risk systems for accuracy, robustness and cybersecurity, and systemic-risk GPAI for the model and its physical infrastructure. Not legal advice. This page does not determine that YOUR system must meet Article 15 or Article 55.

AI Act cybersecurity, last verified 9 September 2026 against Articles 15, 42, 55 and 113 of Regulation (EU) 2024/1689 (OJ L 2024/1689, 12.7.2024). Regulation (EU) 2024/2847 is a different statute — CRA, not the AI Act. ISO/IEC 27001:2022 is a management-system standard, not the regulation. NIST AI RMF 1.0 is guidance, not law. Commission AI Act pages, ENISA AI-threat materials, and the GPAI Code of Practice safety and security chapter are Commission / agency materials — guidance, not the regulation. This page is not legal advice, not a filing, not a determination that YOUR system must meet Article 15 or Article 55 cybersecurity, and does not start a clock. This product does not certify cybersecurity.

This is Articles 15 and 55(1)(d), not YOUR cybersecurity finding

Audience: a CISO, product, engineering, or counsel walking Regulation (EU) 2024/1689 on accuracy, robustness, and cybersecurity. This page is not legal advice. It does not start a clock. Reading it does not start a clock. Mapping a row is not a determination that the Act applies, that YOU are a provider or a deployer, that YOUR system is high-risk, that YOUR model has systemic risk, or that YOUR system must meet Article 15 or Article 55. This page does not certify cybersecurity. This product does not certify cybersecurity.

The AI Act is Regulation (EU) 2024/1689 of 13 June 2024, OJ L 2024/1689, 12.7.2024. ELI: http://data.europa.eu/eli/reg/2024/1689/oj. Article 15 is the high-risk accuracy, robustness, and cybersecurity requirement. Article 55(1)(d) is a different GPAI-with-systemic-risk duty for the model and its physical infrastructure. The CRA docs hub on this site is Regulation (EU) 2024/2847 — a different instrument. The GPAI-systemic-risk guide on this site is the Article 51–55 page. Last verified 9 September 2026. Not legal advice.

  • Statute versus guidance: Articles 15, 42, 55 and 113 of 2024/1689 are legal requirements only if they apply. Recitals are recitals, not operative articles. Commission AI Act pages, ENISA AI-threat materials, and the GPAI Code of Practice safety and security chapter are Commission / agency materials — guidance, not the regulation. ISO/IEC 27001:2022 is a standard, not the Act. NIST AI RMF 1.0 is guidance, not law. This page quotes which kind of text it is relying on.
  • The EU AI Act overview on this site is the pillar page. The requirements-in-force-2026 guide on this site is the Article 113 dates page. The GPAI-systemic-risk guide on this site is the Article 51–55 page. The AI-incident-reporting guide on this site is the Articles 3(49), 55 and 73 page. The AI-risk-management-requirements guide on this site is the Articles 9 and 55 page. The CRA docs hub on this site is live. A dedicated model-evaluation-requirements and readiness-checklist guide is not on this site yet. Naming them is not a link.
  • This page does not invent a 2 August 2025 start date for Article 15. Article 15 sits in Chapter III Section 2. Article 113 of 2024/1689 does not name Chapter III Section 2 in points (a) or (b). The residual second paragraph therefore applies Article 15 from 2 August 2026, except Article 6(1) corresponding obligations. Article 55 sits in Chapter V. Article 113(b) applies Chapter V from 2 August 2025, with the exception of Article 101. Those are two clocks. Article 113(c) keeps Article 6(1) and the corresponding obligations — Annex I product-embedded high-risk — on 2 August 2027, not 2 August 2026. This page does not invent a 2 August 2026 date for Annex I.

Article 15 is not Article 55, and is not the CRA

Do not conflate them. Article 15 is a high-risk AI-system requirement: design and develop so that the system achieves an appropriate level of accuracy, robustness, and cybersecurity throughout its lifecycle. Article 55(1)(d) is a GPAI-model-with-systemic-risk duty: ensure an adequate level of cybersecurity protection for the model and the physical infrastructure of the model. Regulation (EU) 2024/2847 essential cybersecurity requirements — Article 13(1) and Annex I Part I — are a manufacturer duty for products with digital elements. They are not AI Act Article 15. Mapping a row is not a finding that any of those texts bind YOU. Last verified 9 September 2026. Not legal advice.

Article 15 versus Article 55(1)(d) versus CRA essential cybersecurity (not YOUR finding; not a determination that YOUR system must meet them; not legal advice)
TrackWhat the cited text isKind of textLast verified
Article 15 — high-risk accuracy, robustness and cybersecurityHigh-risk AI systems shall be designed and developed in such a way that they achieve an appropriate level of accuracy, robustness, and cybersecurity, and that they perform consistently in those respects throughout their lifecycle. Residual application 2 August 2026 via the Article 113 second paragraph. Article 113(c) Annex I corresponding obligations remain 2 August 2027 in the original regulation. This page does not determine that YOUR system must meet Article 15.Article 15 of 2024/1689. Legal requirement, only if it applies. Distinct from Article 55(1)(d) and from CRA essential cybersecurity requirements. This product does not certify cybersecurity.9 September 2026
Article 55(1)(d) — systemic-risk GPAI cybersecurityProviders of general-purpose AI models with systemic risk shall ensure an adequate level of cybersecurity protection for the general-purpose AI model with systemic risk and the physical infrastructure of the model. In force 2 August 2025 via Article 113(b), except Article 101. The GPAI-systemic-risk guide on this site is the Article 51–55 page.Article 55(1)(d) of 2024/1689. Legal requirement, only if it applies. Distinct from Article 15. This product does not certify cybersecurity.9 September 2026
CRA essential cybersecurity requirements — products with digital elementsRegulation (EU) 2024/2847 Article 13(1) and Annex I Part I are manufacturer duties for products with digital elements. They are not AI Act Article 15. A dedicated CRA vulnerability-management guide is not on this site yet. Naming it is not a link. The CRA docs hub on this site is that instrument.Regulation (EU) 2024/2847. A different statute. Legal requirement of the CRA, only if it applies. Distinct from AI Act Articles 15 and 55. This page is not the CRA.9 September 2026
ISO/IEC 27001:2022 and NIST AI RMF 1.0ISO/IEC 27001:2022 is a management-system standard. NIST AI RMF 1.0 is voluntary US agency guidance. They do not discharge Article 15 or Article 55(1)(d). The ISO 27001 framework guide and the NIST AI RMF framework guide on this site are education pages.Standard and guidance. Not the regulation. Distinct from Articles 15 and 55 and from the CRA.9 September 2026

What original Article 15 actually says

Last verified 9 September 2026 against Article 15 of Regulation (EU) 2024/1689 on EUR-Lex (OJ L 2024/1689, 12.7.2024). These are legal requirements of the original regulation, only if they apply. This page does not apply them to YOUR system. Not legal advice.

Article 15 as the original regulation states it (not YOUR cybersecurity finding; not a determination that YOUR system must meet Article 15; not legal advice)
PointWhat the cited text saysKind of textLast verified
Article 15(1) — appropriate level throughout the lifecycleAuthentic Article 15(1): High-risk AI systems shall be designed and developed in such a way that they achieve an appropriate level of accuracy, robustness, and cybersecurity, and that they perform consistently in those respects throughout their lifecycle.Article 15(1) of 2024/1689. Legal requirement, only if it applies. This page does not score YOUR accuracy, robustness, or cybersecurity.9 September 2026
Article 15(2) — Commission encourages benchmarksTo address the technical aspects of how to measure the appropriate levels of accuracy and robustness set out in paragraph 1 and any other relevant performance metrics, the Commission shall, in cooperation with relevant stakeholders and organisations such as metrology and benchmarking authorities, encourage, as appropriate, the development of benchmarks and measurement methodologies.Article 15(2) of 2024/1689. A Commission duty to encourage. Not a measurement of YOUR system. This page does not invent a Commission benchmark.9 September 2026
Article 15(3) — declare accuracy in the instructions for useAuthentic Article 15(3): The levels of accuracy and the relevant accuracy metrics of high-risk AI systems shall be declared in the accompanying instructions of use.Article 15(3) of 2024/1689. Legal requirement, only if it applies. This page does not write YOUR instructions for use.9 September 2026
Article 15(4) first subparagraph — resilience to errors, faults, inconsistenciesAuthentic Article 15(4): High-risk AI systems shall be as resilient as possible regarding errors, faults or inconsistencies that may occur within the system or the environment in which the system operates, in particular due to their interaction with natural persons or other systems. Technical and organisational measures shall be taken in this regard.Article 15(4) of 2024/1689. Legal requirement, only if it applies. This page does not pick YOUR measures.9 September 2026
Article 15(4) second subparagraph — redundancyThe robustness of high-risk AI systems may be achieved through technical redundancy solutions, which may include backup or fail-safe plans.Article 15(4) of 2024/1689. Legal requirement of a permitted route, only if it applies. This page does not design YOUR redundancy.9 September 2026
Article 15(4) third subparagraph — feedback loopsHigh-risk AI systems that continue to learn after being placed on the market or put into service shall be developed in such a way as to eliminate or reduce as far as possible the risk of possibly biased outputs influencing input for future operations (feedback loops), and as to ensure that any such feedback loops are duly addressed with appropriate mitigation measures.Article 15(4) of 2024/1689. Legal requirement, only if it applies. This page does not find that YOUR system continues to learn.9 September 2026
Article 15(5) first and second subparagraphs — unauthorised third partiesAuthentic Article 15(5): High-risk AI systems shall be resilient against attempts by unauthorised third parties to alter their use, outputs or performance by exploiting system vulnerabilities. The technical solutions aiming to ensure the cybersecurity of high-risk AI systems shall be appropriate to the relevant circumstances and the risks.Article 15(5) of 2024/1689. Legal requirement, only if it applies. This product does not certify cybersecurity.9 September 2026
Article 15(5) third subparagraph — AI-specific vulnerabilitiesThe technical solutions to address AI specific vulnerabilities shall include, where appropriate, measures to prevent, detect, respond to, resolve and control for attacks trying to manipulate the training data set (data poisoning), or pre-trained components used in training (model poisoning), inputs designed to cause the AI model to make a mistake (adversarial examples or model evasion), confidentiality attacks or model flaws.Article 15(5) of 2024/1689. Legal requirement of the named classes, only if it applies. This page does not run YOUR threat model.9 September 2026

What original Article 55(1)(d) actually says

Last verified 9 September 2026 against Article 55 of Regulation (EU) 2024/1689 on EUR-Lex (OJ L 2024/1689, 12.7.2024). Article 55 is in Chapter V. It is not Article 15. The GPAI-systemic-risk guide on this site is the Article 51–55 page. A dedicated model-evaluation-requirements guide is not on this site yet. Naming it is not a link. Not legal advice.

Article 55(1)(d) as the original regulation states it (not YOUR GPAI cybersecurity finding; not Article 15; not legal advice)
PointWhat the cited text saysKind of textLast verified
Article 55(1)(d)Authentic Article 55(1)(d): In addition to the obligations listed in Articles 53 and 54, providers of general-purpose AI models with systemic risk shall ensure an adequate level of cybersecurity protection for the general-purpose AI model with systemic risk and the physical infrastructure of the model.Article 55(1)(d) of 2024/1689. Legal requirement, only if Article 55 applies. Model and physical infrastructure. Distinct from Article 15. This product does not certify cybersecurity.9 September 2026
Article 55(1)(a) — evaluation, including adversarial testing, is a different pointArticle 55(1)(a): perform model evaluation in accordance with standardised protocols and tools reflecting the state of the art, including conducting and documenting adversarial testing of the model with a view to identifying and mitigating systemic risks. That is not Article 55(1)(d). A dedicated model-evaluation-requirements guide is not on this site yet. Naming it is not a link.Article 55(1)(a) of 2024/1689. Legal requirement, only if it applies. Distinct from Article 55(1)(d) cybersecurity. This product does not run adversarial testing for you.9 September 2026
Article 55(2) — codes of practice do not replace paragraph 1Providers of general-purpose AI models with systemic risk may rely on codes of practice within the meaning of Article 56 to demonstrate compliance with the obligations set out in paragraph 1 of this Article, until a harmonised standard is published. Providers who do not adhere to an approved code of practice or do not comply with a European harmonised standard shall demonstrate alternative adequate means of compliance for assessment by the Commission.Article 55(2) of 2024/1689. Legal requirement of the permission, only if it applies. Does not replace Article 55(1)(d). The GPAI Code of Practice, including its safety and security chapter, is guidance, not the regulation.9 September 2026

AI-specific vulnerabilities as Article 15(5) names them

The table below is the Article 15(5) third-subparagraph list. Walking a row is not a finding that YOUR system has that vulnerability, and is not a determination that Article 15 binds YOU. Last verified 9 September 2026. Not legal advice.

Article 15(5) named classes (not YOUR threat model; not a determination that YOUR system must meet Article 15; not legal advice)
Named classWhat the cited text saysWhat this page does not do
Data poisoningattacks trying to manipulate the training data set (data poisoning)Does not find that YOUR training data was poisoned.
Model poisoningor pre-trained components used in training (model poisoning)Does not find that YOUR pre-trained components were poisoned.
Adversarial examples or model evasioninputs designed to cause the AI model to make a mistake (adversarial examples or model evasion)Does not run adversarial testing for you. A dedicated model-evaluation-requirements guide is not on this site yet. Naming it is not a link.
Confidentiality attacksconfidentiality attacksDoes not find a confidentiality attack on YOUR model.
Model flawsor model flawsDoes not score YOUR model flaws. This product does not certify cybersecurity.

Article 42 presumption is not a CRA certificate

Last verified 9 September 2026 against Article 42 of Regulation (EU) 2024/1689 on EUR-Lex (OJ L 2024/1689, 12.7.2024). A presumption of conformity is not a finding that YOUR system meets Article 15. This product does not certify cybersecurity. Not legal advice.

Article 42 as cited (not YOUR certificate; not a determination; not legal advice)
TextWhat the cited text saysKind of textLast verified
Article 42(2) — Cybersecurity Act schemeAuthentic Article 42(2): High-risk AI systems that have been certified or for which a statement of conformity has been issued under a cybersecurity scheme pursuant to Regulation (EU) 2019/881 and the references of which have been published in the Official Journal of the European Union shall be presumed to comply with the cybersecurity requirements set out in Article 15 of this Regulation in so far as the cybersecurity certificate or statement of conformity or parts thereof cover those requirements.Article 42(2) of 2024/1689. Legal requirement of a presumption, only if it applies. Regulation (EU) 2019/881 is the Cybersecurity Act, not the CRA. This product does not issue that certificate.9 September 2026
Regulation (EU) 2026/1744 inserted Article 42(3)The EUR-Lex consolidated record 02024R1689-20260727 presents an inserted Article 42(3): where high-risk AI systems fall within the scope of Regulation (EU) 2024/2847 and the conditions laid down in Article 12(1) of that Regulation are fulfilled, such systems shall be deemed to comply with the cybersecurity requirements set out in Article 15 of this Regulation. That consolidated text is a documentation tool with no legal effect. Counsel reads the authentic operative article of 2026/1744. This page does not apply 2026/1744 to YOU.Amending regulation (EU) 2026/1744 — legal requirement if that regulation applies. Distinct from original Article 42(2). Is not a finding that the CRA discharges Article 15 for YOU.9 September 2026

Does YOUR system have to meet Article 15 or Article 55? — questions, not a finding

The table below is a question list. Answering a row is not a determination that YOUR system must meet Article 15 or Article 55 cybersecurity, not CE marking, and not a CRA finding. Walk it with counsel. Last verified 9 September 2026. Not legal advice.

Questions, not a finding (not YOUR Article 15 file; not a determination that YOUR system must meet Article 15 or Article 55; not legal advice)
QuestionWhat the cited text points atWhat this page does not do
Does the Act apply to YOU at all?Articles 2 and 3 — AI system or GPAI model placed on the Union market, put into service in the Union, or producing output used in the Union, and the Article 2 exclusions.Does not run applicability for YOU.
Are YOU a provider of a high-risk AI system?Articles 3(3), 6, 8 and 16. Article 16(a): providers shall ensure that their high-risk AI systems are compliant with the requirements set out in Section 2, which includes Article 15. The provider-vs-deployer guide on this site is the Articles 3, 16, 25 and 26 page.Does not determine that YOU are a provider. Does not classify YOUR system as high-risk.
If Article 15 is in play, which limbs — accuracy, robustness, cybersecurity, declared metrics, feedback loops, AI-specific vulnerabilities?Article 15(1)–(5). Named AI-specific classes: data poisoning, model poisoning, adversarial examples or model evasion, confidentiality attacks, model flaws.Does not pick YOUR limbs. Does not run YOUR threat model.
Are YOU a provider of a GPAI model with systemic risk? If so, Article 55(1)(d) is a different duty.Article 55(1)(d): adequate level of cybersecurity protection for the model and the physical infrastructure of the model. In force 2 August 2025 under Article 113(b), except Article 101. The GPAI-systemic-risk guide on this site is the Article 51–55 page.Does not designate YOUR model. Does not certify cybersecurity.
Is this the CRA?No. CRA essential cybersecurity requirements are Regulation (EU) 2024/2847 Article 13(1) and Annex I Part I. Different statute, different addressees (manufacturer of a product with digital elements), different essential requirements. The CRA docs hub on this site is that instrument. A dedicated CRA vulnerability-management guide is not on this site yet. Naming it is not a link.Does not run the CRA test. Is not the CRA.
Does this page mean we must CE-mark?No. CE marking for high-risk AI systems is Articles 16(h) and 48, only if those articles apply. Mapping a row on this page is not a conformity assessment, not an EU declaration of conformity, and not CE marking.Does not CE-mark. Does not run conformity assessment. This product does not issue certifications.
Do ISO 27001 or NIST AI RMF discharge Article 15 or Article 55(1)(d)?No. ISO/IEC 27001:2022 is a standard. NIST AI RMF 1.0 is guidance. They are complementary practice, not the Act.Does not treat a standard or a framework as discharging Article 15 or Article 55.

Article 113: Article 55 is 2 August 2025; Article 15 is residual 2 August 2026

Last verified 9 September 2026 against Article 113 of Regulation (EU) 2024/1689 on EUR-Lex (OJ L 2024/1689, 12.7.2024). Article 55 sits in Chapter V. Article 113(b): Chapter III Section 4, Chapter V, Chapter VII and Chapter XII and Article 78 shall apply from 2 August 2025, with the exception of Article 101. The GPAI cybersecurity duty in Article 55(1)(d) therefore applies from 2 August 2025 under Article 113(b), except Article 101. It did not start on 2 August 2026. This page does not invent a 2 August 2026 start date for GPAI.

Article 15 sits in Chapter III Section 2 (requirements for high-risk AI systems). Article 113 of 2024/1689 does not name Chapter III Section 2 in points (a) or (b). The residual second paragraph — 'It shall apply from 2 August 2026' — therefore applies Article 15 from 2 August 2026. This page does not invent a 2 August 2025 start date for Article 15 high-risk cybersecurity. Those two clocks are not one number.

Article 113(c) keeps Article 6(1) and the corresponding obligations — Annex I product-embedded high-risk — on 2 August 2027, not 2 August 2026. This page does not invent a 2 August 2026 date for Annex I. Regulation (EU) 2026/1744 is an amending regulation. Recital 40 of that regulation and the EUR-Lex consolidated record present Chapter III Sections 1, 2 and 3 as applying from 2 December 2027 for Annex III and 2 August 2028 for Annex I. Recital 40 is a recital. The consolidated record is a documentation tool with no legal effect. Counsel reads the authentic operative article of any amendment. This page does not apply 2026/1744 to YOU. It does not rewrite Article 113(b) for Chapter V, and it does not rewrite the original residual date or original Article 113(c) in the original regulation. Not legal advice.

What to do now

As of last verification on 9 September 2026, Article 55 GPAI duties, including Article 55(1)(d), have applied since 2 August 2025 under Article 113(b), except Article 101. Article 15 high-risk accuracy, robustness, and cybersecurity has applied since 2 August 2026 under the Article 113 residual second paragraph. Article 113(c) Annex I remains 2 August 2027 in the original regulation. The list below is operational preparation. It is not a determination that YOUR system must meet Article 15 or Article 55. Walk it with counsel.

  • Ask counsel whether YOU are a provider of a high-risk AI system under Articles 3(3) and 6, or a provider of a GPAI model with systemic risk under Articles 51–55. This page does not run those tests. Marking eu_ai_act in an obligation map is not that determination and is not a cybersecurity determination.
  • If counsel finds Article 15 in play, walk Article 15(1)–(5) as written: appropriate accuracy, robustness, and cybersecurity throughout the lifecycle; declared accuracy metrics; resilience to errors; feedback-loop mitigation where the system continues to learn; AI-specific vulnerabilities including data poisoning, model poisoning, adversarial examples or model evasion, confidentiality attacks, and model flaws. Do not date Article 15 from 2 August 2025. Do not treat it as the CRA. This product does not certify cybersecurity.
  • If counsel finds Article 55(1)(d) in play, walk that point as written: adequate cybersecurity protection for the model and the physical infrastructure of the model. That is not Article 15. Do not date Article 55 from 2 August 2026. Article 113(b) is 2 August 2025.
  • The EU AI Act overview on this site is the pillar page. The requirements-in-force-2026 guide on this site is the Article 113 dates page. The GPAI-systemic-risk guide on this site is the Article 51–55 page. The AI-incident-reporting guide on this site is the Articles 3(49), 55 and 73 page. The CRA docs hub on this site is live. A dedicated model-evaluation-requirements and readiness-checklist guide is not on this site yet. Naming them is not a link.

Checklist

This is a question list, not a determination that YOUR system must meet Article 15 or Article 55, and not a certificate. Walk it with counsel. The GPAI-systemic-risk guide on this site is the Article 51–55 page. The CRA docs hub on this site is live.

  • Does the Act apply to YOU at all? Articles 2 and 3. This page does not run that test.
  • Are YOU a provider of a high-risk AI system? Articles 6, 8, 15 and 16. This page does not determine that YOU are a provider and does not classify YOUR system.
  • If Article 15 is in play, which limbs? This page does not pick them and does not run YOUR threat model.
  • Is Article 55(1)(d) a different duty on YOUR facts? Model and physical infrastructure, in force 2 August 2025 under Article 113(b). This page does not designate YOUR model.
  • Is this the CRA? No. Different statute, different essential requirements, different addressees.
  • Does this page mean we must CE-mark? No. Articles 16(h) and 48 are a different duty, only if they apply.
  • Did Article 15 high-risk cybersecurity start 2 August 2025? No. Residual Article 113 second paragraph is 2 August 2026.
  • Did Article 55 GPAI cybersecurity start 2 August 2026? No. Article 113(b) is 2 August 2025.
  • Does this page start a clock, or does the product certify cybersecurity? No. This product does not certify cybersecurity and does not start a clock.
  • Document the assessment, including a not-in-scope decision. This page does not keep YOUR file.

Where this shows up in ShipReady Metrics

The bundled framework key eu_ai_act is customer-visible. Its version label is Regulation (EU) 2024/1689 high-risk obligations (starter subset). It is not in INTERNAL_TESTER_ONLY_FRAMEWORKS. The control-set is a starter subset, illustrative, to be tailored by a compliance owner; not legal advice; not a conformity determination; not CE marking. Readiness is not compliance and not an EU-database registration.

If you already have a session: signed-in app → Compliance → AI governance holds the AI inventory and AI-governance posture. The AI risk register lives with that AI-governance surface. That inventory can record facts the organisation declared. Recording a row is not an Article 15 file, is not an Article 55(1)(d) finding, is not a determination that YOUR system must meet Article 15 or Article 55, and is not a clock. Marking in-scope is not a cybersecurity determination and not a certificate. A named human still owns the assessment.

This product does not certify cybersecurity, does not CE-mark, does not run Article 15 for you, does not designate a GPAI model, does not start a reporting clock, and does not issue certifications. The obligation map lists frameworks the organisation has marked in-scope, including eu_ai_act if that mark is set. Marking eu_ai_act in-scope is not a determination that you must meet Article 15 or Article 55. The cyber risk register lives under Security. It is not an Article 15 cybersecurity file. Vulnerability management on this product (KEV / EPSS / CVSS) is a shipped scanning surface. It is not Article 15 and is not the CRA.

This page does not document a public demo URL. There is no public EU AI Act demo path. This product does not start a clock.

Primary sources (last verified 9 September 2026)

Every regulatory or guidance claim on this page is taken from one of these. If a later revision of a source changes the rule, the date above is how you can see we have not re-checked yet.

Regulation (EU) 2024/1689 of 13 June 2024 (Artificial Intelligence Act), Articles 15, 42, 55 and 113, is a legal requirement only if it applies. Entry into force 1 August 2024. Article 113(a) 2 February 2025; Article 113(b) 2 August 2025; general application 2 August 2026; Article 113(c) Article 6(1) from 2 August 2027. Article 55 is Chapter V and applies from 2 August 2025 under Article 113(b), except Article 101. Article 15 is Chapter III Section 2 and applies from 2 August 2026 under the residual second paragraph. Regulation (EU) 2024/2847 Article 13(1) and Annex I Part I are a different statute. Regulation (EU) 2019/881 is the Cybersecurity Act, named by Article 42(2). ISO/IEC 27001:2022 is a standard. NIST AI RMF 1.0 is guidance. Commission AI Act pages, ENISA AI-threat materials, and the GPAI Code of Practice safety and security chapter are Commission / agency materials — guidance, not the regulation. Regulation (EU) 2026/1744 is an amending regulation. These are not a complete world list. Not legal advice.

The EU AI Act overview on this site is the pillar page. The requirements-in-force-2026 guide on this site is the Article 113 dates page. The GPAI-requirements guide on this site is the Article 53 baseline page. The GPAI-systemic-risk guide on this site is the Article 51–55 page. The provider-vs-deployer guide on this site is the Articles 3, 16, 25 and 26 page. The AI-governance-requirements guide on this site is the Articles 4, 14, 26 and ISO 42001 page. The AI-risk-management-requirements guide on this site is the Articles 9 and 55 page. The AI-incident-reporting guide on this site is the Articles 3(49), 55 and 73 page. The EU AI Act framework guide on this site is the education page under frameworks. The CRA docs hub on this site is live. A dedicated model-evaluation-requirements and readiness-checklist guide is not on this site yet. Naming them is not a link.

Frequently asked questions