Operational guidance, not legal advice. This page distills named public sources (regulator guidance and industry practice). It is not a legal determination, not a notification decision, and not a substitute for your counsel, insurer, or a retained DFIR firm. Verify applicability and current deadlines for your facts and jurisdiction.
What is the EU AI Act and when does it apply?
Updated
The EU AI Act (Regulation (EU) 2024/1689) is a regulation laying down harmonised rules on artificial intelligence. It uses risk-based duties: prohibited practices, high-risk systems, transparency obligations, and residual systems. This page is not legal advice and does not determine that the Act applies to YOU.
EU AI Act overview, last verified 9 September 2026 against Regulation (EU) 2024/1689 Articles 1–6, 50, 51–56, 99 and 113 and Annexes I and III, OJ L 2024/1689 of 12 July 2024, and against Regulation (EU) 2026/1744 (Digital Omnibus on AI, OJ L 1744, 24 July 2026) as an amending regulation. Commission AI Act pages and AI Office materials are Commission materials — guidance, not the regulation. It is not legal advice, not a filing, not a determination that the Act applies to YOU, and does not start a clock.
This is the AI Act, not YOUR applicability
Audience: a CTO, founder, product, or compliance lead at an organisation that might place AI systems or general-purpose AI models on the Union market, put them into service in the Union, or deploy them where output is used in the Union. This page is not legal advice. It does not start a clock. Reading it does not start a clock. Mapping a row is not a determination that the Act applies, that you are a provider or a deployer, or that you must file.
The AI Act is Regulation (EU) 2024/1689 of 13 June 2024, OJ L 2024/1689, 12.7.2024. ELI: http://data.europa.eu/eli/reg/2024/1689/oj. It is a regulation, directly applicable. It is not the CRA, not NIS2, not GDPR, and not ISO/IEC 42001. The CRA docs hub and the EU AI Act framework guide on this site are different instruments. Last verified 9 September 2026. Not legal advice.
- Statute versus guidance: Articles 1–6, 50, 51–56, 99 and 113, and Annexes I and III, are legal requirements only if they apply. Commission AI Act pages and AI Office materials are Commission materials — guidance, not the regulation. This page quotes which kind of text it is relying on.
- The requirements-in-force-2026 guide on this site is the Article 113 dates page. A dedicated GPAI-requirements, provider-vs-deployer, and readiness-checklist guide is not on this site yet. An ISO 42001 versus EU AI Act comparison is not on this site yet. Naming them is not a link.
- The EU AI Act framework guide on this site is the education page under frameworks. That page is a different kind and a different path from this help cluster. This cluster does not reuse that slug.
What the AI Act is — Articles 1, 2 and 3
Article 1: this Regulation lays down harmonised rules for the placing on the market, the putting into service and the use of AI systems in the Union; prohibitions of certain AI practices; specific requirements for high-risk AI systems and obligations for operators of such systems; transparency rules for certain AI systems; rules on the placing on the market of general-purpose AI models; rules on market monitoring, market surveillance, governance and enforcement. That is the legal requirement.
Article 2 sets territorial and personal scope, including providers irrespective of where they are established, deployers established or located in the Union, and providers and deployers in third countries where the output produced by the AI system is used in the Union. Articles 2(3)–(12) set exclusions and carve-outs (including certain national-security, military, research, and personal non-professional uses). This page does not run those exclusions for YOU.
Article 3 definitions, quoted as the regulation uses them. This page does not apply them to YOU. Last verified 9 September 2026. Not legal advice.
| Term | What Article 3 says | Kind of text | Last verified |
|---|---|---|---|
| AI system — Article 3(1) | A machine-based system that is designed to operate with varying levels of autonomy and that may exhibit adaptiveness after deployment, and that, for explicit or implicit objectives, infers, from the input it receives, how to generate outputs such as predictions, content, recommendations, or decisions that can influence physical or virtual environments. | Legal requirement — Article 3(1). This page does not find that YOUR software is an AI system. | 9 September 2026 |
| Provider — Article 3(3) | A natural or legal person, public authority, agency or other body that develops an AI system or a general-purpose AI model or that has an AI system or a general-purpose AI model developed and places it on the market or puts the AI system into service under its own name or trademark, whether or not a price is charged. | Legal requirement — Article 3(3). This page does not find that YOU are a provider. | 9 September 2026 |
| Deployer — Article 3(4) | A natural or legal person, public authority, agency or other body using an AI system under its authority except where the AI system is used in the course of a personal non-professional activity. | Legal requirement — Article 3(4). This page does not find that YOU are a deployer. | 9 September 2026 |
| Placing on the market — Article 3(9) | The first making available of an AI system or a general-purpose AI model on the Union market. | Legal requirement — Article 3(9). This page does not find that YOUR supply is that activity. | 9 September 2026 |
| Putting into service — Article 3(11) | The supply of an AI system for first use directly to the deployer or for own use in the Union for its intended purpose. | Legal requirement — Article 3(11). | 9 September 2026 |
| General-purpose AI model — Article 3(63) | An AI model, including where such an AI model is trained with a large amount of data using self-supervision at scale, that displays significant generality and is capable of competently performing a wide range of distinct tasks regardless of the way the model is placed on the market and that can be integrated into a variety of downstream systems or applications, except AI models that are used for research, development or prototyping activities before they are placed on the market. | Legal requirement — Article 3(63). GPAI is a separate Chapter V track, not one of the four system-risk categories. This page does not classify YOUR model. | 9 September 2026 |
Does the Act apply? — questions, not YOUR answer
Walk these questions with counsel. Answering them here would be a determination. This page does not make that determination. Last verified 9 September 2026. Not legal advice.
| Question | What the regulation points at | Kind of text | What this page does not do |
|---|---|---|---|
| Is there an AI system or a GPAI model? | Article 3(1) and Article 3(63). | Legal requirement — only if it applies. | Does not classify YOUR software. |
| Is it placed on the Union market, put into service in the Union, or is the output used in the Union? | Article 2(1). Extraterritorial reach is in the article, not a slogan. | Legal requirement — Article 2(1). | Does not find that YOUR output is used in the Union. |
| Which operator role, if any? | Provider, deployer, importer, distributor, product manufacturer, authorised representative — Articles 2 and 3. | Legal requirement. | Does not assign YOU a role. |
| Does an Article 2 exclusion apply? | Articles 2(3)–(12) list carve-outs. Counsel reads them against YOUR facts. | Legal requirement — the exclusions, only if they apply. | Does not run the exclusion for YOU. |
Phased timeline — Article 113, not YOUR dates
Last verified 9 September 2026 against Article 113 of Regulation (EU) 2024/1689 on EUR-Lex (OJ L 2024/1689, 12.7.2024). Article 113 first paragraph: this Regulation shall enter into force on the twentieth day following that of its publication in the Official Journal. Publication was 12 July 2024, so entry into force is 1 August 2024. Article 113 second paragraph: this Regulation shall apply from 2 August 2026. However: (a) Chapters I and II shall apply from 2 February 2025; (b) Chapter III Section 4, Chapter V, Chapter VII and Chapter XII and Article 78 shall apply from 2 August 2025, with the exception of Article 101; (c) Article 6(1) and the corresponding obligations in this Regulation shall apply from 2 August 2027. Those dates are not one number. This page does not move them.
Article 113(c) of the original regulation assigns Article 6(1) — high-risk classification for AI systems that are safety components of products already covered by Union harmonisation legislation listed in Annex I — to 2 August 2027. This page does not invent a 2 August 2026 date for Annex I product-embedded high-risk. The original 2 August 2026 date is the general application of the rest of the Regulation, which included Annex III high-risk under Article 6(2) and Chapter IV transparency (Article 50) because those provisions were not in the (a), (b), or (c) exceptions.
Regulation (EU) 2026/1744 of 8 July 2026 (Digital Omnibus on AI), OJ L 1744, 24.7.2026, is an amending regulation. EUR-Lex records it as in force from 27 July 2026 and as amending 2024/1689 (consolidated record 02024R1689-20260727; that consolidated text is a documentation tool with no legal effect). The Commission's AI Act page (last update 3 August 2026) presents the amended high-risk dates as 2 December 2027 for systems classified under Article 6(2) and Annex III, and 2 August 2028 for systems classified under Article 6(1) and Annex I. Those Commission dates are Commission materials summarising the amending regulation, not a substitute for the authentic OJ text of 2026/1744. Counsel reads the amending regulation. This table is not YOUR dates. Not legal advice.
| Date in the cited text | What applies | Kind of text | Last verified |
|---|---|---|---|
| 1 August 2024 | Entry into force — twentieth day following publication in the Official Journal (OJ L 2024/1689, 12.7.2024). | Article 113 first paragraph of 2024/1689. Legal requirement. | 9 September 2026 |
| 2 February 2025 | Chapters I and II — including Article 4 AI literacy and Article 5 prohibited practices. | Article 113(a) of 2024/1689. Legal requirement. | 9 September 2026 |
| 2 August 2025 | GPAI (Chapter V), governance (Chapter VII), penalties (Chapter XII), notifying authorities and notified bodies (Chapter III Section 4), and Article 78; except Article 101. | Article 113(b) of 2024/1689. Legal requirement. | 9 September 2026 |
| 2 August 2026 | General application of the rest of the original Regulation. Originally included Annex III high-risk (Article 6(2)) and Article 50 transparency. Not the Annex I product-embedded high-risk date. | Article 113 second paragraph of 2024/1689. Legal requirement of the original regulation. | 9 September 2026 |
| 2 August 2027 | Article 6(1) and the corresponding obligations — Annex I product-embedded high-risk. Not 2 August 2026. | Article 113(c) of 2024/1689 as originally enacted. Legal requirement of the original regulation. | 9 September 2026 |
| 2 December 2027 | High-risk obligations for AI systems classified under Article 6(2) and Annex III, as the Commission AI Act page and the EUR-Lex consolidated record present the 2026/1744 amendment. | Amending regulation (EU) 2026/1744 — legal requirement if that regulation applies. Commission page is guidance on the amendment, not the OJ article itself. | 9 September 2026 |
| 2 August 2028 | High-risk obligations for AI systems classified under Article 6(1) and Annex I, as the Commission AI Act page and the EUR-Lex consolidated record present the 2026/1744 amendment. | Amending regulation (EU) 2026/1744 — legal requirement if that regulation applies. Not a 2 August 2026 date. | 9 September 2026 |
Risk tiers — unacceptable, high, limited, minimal
The Commission AI Act page describes four levels of risk. The regulation itself does not use 'limited' and 'minimal' as operative headings. It uses prohibited AI practices (Article 5), high-risk AI systems (Article 6 and Annexes I and III), transparency obligations (Article 50), and codes of conduct (Article 95). GPAI models are a separate Chapter V track. This page does not classify YOUR system. Last verified 9 September 2026. Not legal advice.
| Category | What the cited text says | Kind of text | Last verified |
|---|---|---|---|
| Unacceptable — prohibited practices | Article 5 prohibits listed AI practices (including certain manipulative or exploitative techniques, social scoring, untargeted scraping of facial images, emotion recognition in the workplace or education with listed exceptions, certain biometric categorisation, and real-time remote biometric identification in publicly accessible spaces for law enforcement outside listed exceptions). The system may not be placed on the market, put into service, or used for a prohibited practice. | Legal requirement — Article 5, only if it applies. Commission 'unacceptable risk' label is Commission materials. | 9 September 2026 |
| High-risk | Article 6(1): an AI system is high-risk where it is intended to be used as a safety component of a product, or is itself a product, covered by Union harmonisation legislation listed in Annex I, and that product is required to undergo a third-party conformity assessment. Article 6(2): AI systems referred to in Annex III are high-risk (biometrics, critical infrastructure, education, employment, essential services, law enforcement, migration and border control, administration of justice and democratic processes), subject to Article 6(3). | Legal requirement — Article 6 and Annexes I and III. This page does not place YOUR system in Annex I or Annex III. | 9 September 2026 |
| Limited — transparency | Article 50 sets transparency obligations for certain AI systems, including systems intended to interact directly with natural persons, emotion-recognition and biometric-categorisation systems, and systems that generate synthetic audio, image, video or text content. People must be informed in the cases the article sets. The Commission page calls this 'limited' or 'transparency' risk. | Legal requirement — Article 50, only if it applies. 'Limited risk' is Commission terminology, not an Article 6 heading. | 9 September 2026 |
| Minimal — residual | AI systems that are not prohibited, not high-risk, and not in the Article 50 transparency cases carry no additional mandatory AI-Act obligations of those kinds. Article 95 encourages codes of conduct. The Commission page calls this minimal or no risk. | Article 95 codes of conduct are voluntary. 'Minimal risk' is Commission terminology. This page does not find that YOUR system is residual. | 9 September 2026 |
GPAI is a separate track — Chapter V, not a fifth pyramid layer
Chapter V (Articles 51–56) sets obligations for providers of general-purpose AI models. Article 53 is the baseline (technical documentation, information for downstream providers, a copyright policy, a public summary of training content). Article 55 adds duties for GPAI models with systemic risk. Those duties applied from 2 August 2025 under Article 113(b), except Article 101. The GPAI Code of Practice is a voluntary compliance tool published by the Commission — guidance, not the regulation.
A dedicated GPAI-requirements guide is not on this site yet. Naming it is not a link. This page does not find that YOU are a GPAI provider and does not run the systemic-risk threshold. Last verified 9 September 2026. Not legal advice.
Penalties — Article 99 maxima, not typical fines
Article 99(1): Member States shall lay down the rules on penalties and other enforcement measures. The penalties provided for shall be effective, proportionate and dissuasive. Article 99(3): non-compliance with the prohibition of the AI practices referred to in Article 5 shall be subject to administrative fines of up to EUR 35 000 000 or, if the offender is an undertaking, up to 7 % of its total worldwide annual turnover for the preceding financial year, whichever is higher.
Article 99(4) sets a lower ceiling (up to EUR 15 000 000 or 3 % of that turnover, whichever is higher) for non-compliance with listed provisions related to operators or notified bodies other than Article 5. Article 99(5) sets a further ceiling (up to EUR 7 500 000 or 1 % of that turnover, whichever is higher) for supplying incorrect, incomplete or misleading information to notified bodies or national competent authorities. Article 99(6): for SMEs, including start-ups, each fine is up to the percentages or the amount, whichever is lower. Those figures are statutory maxima, not typical fines, and not a prediction. This product does not issue fines. Last verified 9 September 2026. Not legal advice.
| Ceiling | What Article 99 attaches it to | Kind of text | Last verified |
|---|---|---|---|
| Up to EUR 35 000 000 or 7 % of worldwide annual turnover, whichever is higher | Non-compliance with the Article 5 prohibitions — Article 99(3). | Legal requirement — Article 99(3). Statutory maximum, not a typical fine. | 9 September 2026 |
| Up to EUR 15 000 000 or 3 % of worldwide annual turnover, whichever is higher | Non-compliance with listed operator or notified-body provisions other than Article 5 — Article 99(4). | Legal requirement — Article 99(4). This page does not inflate the ceiling. | 9 September 2026 |
| Up to EUR 7 500 000 or 1 % of worldwide annual turnover, whichever is higher | Incorrect, incomplete or misleading information to notified bodies or national competent authorities — Article 99(5). | Legal requirement — Article 99(5). | 9 September 2026 |
Legal requirement versus Commission and AI Office guidance
The table below labels each text. Do not treat guidance as the article, and do not treat the article as optional because a FAQ exists. Last verified 9 September 2026. Not legal advice.
| Text | What it is | What this page does not do |
|---|---|---|
| Regulation (EU) 2024/1689 Articles 1–6, 50, 51–56, 99, 113 and Annexes I–III | Legal requirement — the regulation, only if it applies. | Does not apply those articles to YOU. |
| Regulation (EU) 2026/1744 (Digital Omnibus on AI), OJ L 1744, 24.7.2026 | Amending regulation. Legal requirement if it applies. In force 27 July 2026 per the Commission AI Act page and the EUR-Lex record. | Does not treat a Commission summary as a substitute for the authentic OJ text. |
| European Commission AI Act page (last update 3 August 2026) and AI Act Service Desk | Commission materials. Guidance, not the regulation. | Does not treat a Commission pyramid as rewriting Article 6. |
| EU AI Office GPAI Code of Practice, prohibited-practice guidelines, and GPAI-scope guidelines | Commission / AI Office guidance, not the regulation. The Code of Practice is a voluntary compliance tool. | Does not treat the Code as replacing Article 53 or Article 55. |
How this differs from the CRA, NIS2, GDPR, and ISO 42001
Do not paste one instrument onto another. The CRA docs hub on this site is Regulation (EU) 2024/2847. The NIS2 incident-reporting guide on this site is Directive (EU) 2022/2555 Article 23. The GDPR breach-notification guide on this site is Articles 33–34. ISO/IEC 42001 is a voluntary management-system standard, not a Union regulation. Last verified 9 September 2026. Not legal advice.
- The CRA is a regulation on products with digital elements made available on the Union market. The AI Act is a regulation on AI systems and GPAI models. Filing a CRA Article 14 report does not discharge an AI Act duty.
- NIS2 is a directive on essential and important entities. It is not the AI Act.
- GDPR is a regulation on personal data. An AI system that processes personal data can sit under both. The AI Act does not replace the GDPR.
- ISO/IEC 42001 can evidence an AI management system. It is not a determination that the AI Act is met. An ISO 42001 versus EU AI Act comparison is not on this site yet. Naming it is not a link. The ISO 42001 framework guide on this site is live.
What to do now
As of last verification on 9 September 2026, Article 5 prohibitions and Article 4 literacy have applied since 2 February 2025, GPAI and penalties since 2 August 2025, and the original general-application date of 2 August 2026 has passed. High-risk dates for Annex III and Annex I were amended by 2026/1744 as the Commission page presents them. The list below is operational preparation. It is not a determination that the Act applies to YOU, that you are a provider or a deployer, or that a clock has started. Walk it with counsel.
- Ask counsel whether YOU place an AI system or GPAI model on the Union market, put one into service in the Union, or deploy one whose output is used in the Union. This page does not run that test. Marking eu_ai_act in an obligation map is not that determination.
- Ask counsel which role, if any, YOU occupy — provider, deployer, importer, distributor. A dedicated provider-vs-deployer guide is not on this site yet. Naming it is not a link.
- Inventory the AI systems and models you actually run. Readiness in this product is not a classification and not an EU-database registration.
- Do not treat Commission or AI Office guidance as the regulation. Do not treat this product's eu_ai_act control-set as a conformity-assessment file.
- The requirements-in-force-2026 guide on this site is the Article 113 dates page. A dedicated GPAI-requirements and readiness-checklist guide is not on this site yet. Naming them is not a link.
Checklist
This is a question list, not a filing, and not YOUR notice. Walk it with counsel. The EU AI Act framework guide on this site is the education page under frameworks.
- Does the Act apply? AI system or GPAI model placed on the Union market, put into service in the Union, or producing output used in the Union — Articles 2 and 3. This page does not run that test.
- Which tier, if any — prohibited, high-risk, transparency, or residual? Articles 5, 6 and 50. This page does not place YOUR system.
- Which role, if any — provider or deployer? Articles 3(3) and 3(4). This page does not assign it.
- Article 113 dates are not one number. Original Annex I high-risk is 2 August 2027, not 2 August 2026. Counsel reads 2026/1744 for the amended high-risk dates.
- Article 99 maxima are not typical fines. This product does not issue fines.
- Document the assessment, including a not-in-scope decision. This page does not keep YOUR file.
Where this shows up in ShipReady Metrics
The bundled framework key eu_ai_act is customer-visible. Its version label is Regulation (EU) 2024/1689 high-risk obligations (starter subset). It is not in INTERNAL_TESTER_ONLY_FRAMEWORKS. The control-set is a starter subset, illustrative, to be tailored by a compliance owner; not legal advice; not a conformity determination; not CE marking. Readiness is not compliance and not an EU-database registration.
If you already have a session: signed-in app → Compliance → AI governance holds the AI inventory and AI-governance posture. The AI risk register lives with that AI-governance surface. That inventory does not classify YOUR system under Article 6, does not decide that the Act applies, and does not file with the AI Office or a market-surveillance authority. A named human still owns the assessment.
The obligation map lists frameworks the organisation has marked in-scope, including eu_ai_act if that mark is set. Marking eu_ai_act in-scope is not a determination that you are a provider or a deployer, not a determination that an AI system has been placed on the Union market, and not auto-filing. The cyber risk register lives under Security. It is not an Article 73 serious-incident file.
This page does not document a public demo URL. There is no public EU AI Act demo path. This product does not issue certifications and does not start a clock.
Primary sources (last verified 9 September 2026)
Every regulatory or guidance claim on this page is taken from one of these. If a later revision of a source changes the rule, the date above is how you can see we have not re-checked yet.
Regulation (EU) 2024/1689 of 13 June 2024 (Artificial Intelligence Act), Articles 1–6, 50, 51–56, 99 and 113 and Annexes I and III, is a legal requirement only if it applies. Entry into force 1 August 2024. Article 113(a) 2 February 2025; Article 113(b) 2 August 2025; general application 2 August 2026; Article 113(c) Article 6(1) from 2 August 2027. Regulation (EU) 2026/1744 (Digital Omnibus on AI) is an amending regulation. The European Commission's AI Act page (last update 3 August 2026) and the AI Act Service Desk are Commission materials, not the regulation. EU AI Office GPAI materials are agency/Commission guidance, not the regulation. Regulation (EU) 2024/2847 is a different instrument; the CRA docs hub is on this site. These are not a complete world list. Not legal advice.
The EU AI Act framework guide on this site is the education page under frameworks. The ISO 42001 framework guide on this site is live. The CRA docs hub on this site is live. The requirements-in-force-2026 guide on this site is the Article 113 dates page. A dedicated GPAI-requirements, provider-vs-deployer, and readiness-checklist guide is not on this site yet. An ISO 42001 versus EU AI Act comparison is not on this site yet. Naming them is not a link.
Frequently asked questions
Is this legal advice?
No. It is a pillar overview distilled from Regulation (EU) 2024/1689, with Commission and AI Office materials labelled as guidance, not the regulation. Whether the Act applies to YOU is a legal question for counsel on your facts. This page does not start a clock and does not determine that the Act applies.
Does ShipReady determine that the AI Act applies, or file with the AI Office?
No. The signed-in app does not file with the AI Office or a market-surveillance authority, does not start a clock, and does not decide that the Act applies or that you are a provider or a deployer. Compliance → AI governance tracks the AI inventory and AI-governance posture the organisation recorded. A named human still owns the assessment.
Does marking EU AI Act in-scope mean the Act applies to us?
No. Marking the bundled framework key eu_ai_act in-scope on the obligation map is not a determination that you are a provider or a deployer, or that an AI system has been placed on the Union market. Counsel applies Articles 2 and 3 to YOUR facts.
Does 2 August 2026 apply Annex I product-embedded high-risk obligations?
No. Article 113(c) of Regulation (EU) 2024/1689 as originally enacted assigns Article 6(1) — Annex I product-embedded high-risk — to 2 August 2027, not 2 August 2026. The original 2 August 2026 date is general application of the rest of the Regulation. Regulation (EU) 2026/1744 later amended high-risk dates; the Commission AI Act page presents Annex III as 2 December 2027 and Annex I as 2 August 2028. Counsel reads the amending regulation. Last verified 9 September 2026.
Does ISO 42001 discharge the EU AI Act?
No. ISO/IEC 42001 is a voluntary management-system standard. The AI Act is Regulation (EU) 2024/1689. Running an ISO 42001 programme is not a determination that the Act is met. An ISO 42001 versus EU AI Act comparison is not on this site yet. The ISO 42001 framework guide on this site is live.
Published by ShipReady Metrics, an evidence-based technology and compliance intelligence platform. This guide is educational and vendor-neutral.