The EU AI Act: risk tiers, obligations, and timeline
Updated
The EU AI Act (Regulation (EU) 2024/1689) is the first comprehensive AI law. It classifies AI systems by risk — unacceptable (banned), high-risk, limited, and minimal — and places the heaviest obligations on providers and deployers of high-risk systems, phased in between 2025 and 2027.
This guide explains the four risk tiers, the prohibited practices in Article 5, what providers of high-risk systems must build (risk management, data governance, technical documentation, logging, human oversight, accuracy and cybersecurity), the narrower duties on deployers, the rules for general-purpose AI models, and the phased dates on which each set of obligations starts to apply.
What the EU AI Act is
The EU AI Act is Regulation (EU) 2024/1689, the European Union's horizontal law on artificial intelligence. It entered into force on 1 August 2024 and applies its obligations in phases rather than all at once. The Act takes a risk-based approach: instead of regulating every AI system identically, it sorts systems by the level of risk they pose to health, safety, and fundamental rights, and scales the obligations accordingly.
Its reach is extraterritorial. The Act applies to providers that place AI systems on the EU market or put them into service in the EU regardless of where the provider is established, and to providers and deployers located outside the EU where the output of the system is used within the EU. Because of that scope, organizations well beyond Europe assess whether their AI systems fall in scope, much as they did with the GDPR.
The Act sits alongside — not on top of — existing EU law. It does not replace the GDPR, product-safety directives, or sector rules; it adds AI-specific obligations that operate in parallel. Enforcement is shared between national market-surveillance authorities and, for general-purpose AI models, a central AI Office within the European Commission.
The four risk tiers
Every AI system in scope falls into one of four tiers. The tier determines the obligations. Most systems in ordinary business use fall into the minimal-risk tier, which carries no mandatory obligations under the Act; the regulatory weight concentrates on the high-risk tier.
| Tier | What it covers | Core obligation |
|---|---|---|
| Unacceptable risk | Practices banned under Article 5 (e.g. social scoring, certain manipulative or exploitative uses) | Prohibited — the system may not be placed on the market or used |
| High risk | Systems in Annex I (safety components of regulated products) and Annex III (eight defined areas such as employment, essential services, biometrics) | Full set of provider obligations plus conformity assessment before market entry |
| Limited risk | Systems that interact with people or generate content (e.g. chatbots, synthetic media) | Transparency duties — people must be told they are dealing with AI or with AI-generated content |
| Minimal risk | The large majority of AI systems (e.g. spam filters, recommendation features) | No mandatory obligations; voluntary codes of conduct are encouraged |
Prohibited practices (Article 5)
The unacceptable-risk tier is defined by Article 5, which lists AI practices banned outright because they are considered a clear threat to people's rights and safety. These prohibitions were the first substantive obligations to take effect. In broad terms, the banned categories include:
- Subliminal, manipulative, or deceptive techniques that materially distort behavior and cause harm.
- Exploiting vulnerabilities related to age, disability, or a specific social or economic situation to distort behavior.
- Social scoring — evaluating or classifying people over time based on behavior or characteristics leading to detrimental treatment.
- Assessing or predicting the risk of a person committing a crime based solely on profiling or personality traits.
- Untargeted scraping of facial images from the internet or CCTV to build facial-recognition databases.
- Inferring emotions in the workplace or in education, except for medical or safety reasons.
- Biometric categorization that infers sensitive attributes such as race, political views, or sexual orientation.
- Real-time remote biometric identification in publicly accessible spaces for law-enforcement purposes, outside narrowly defined exceptions.
High-risk systems and what providers must do
High-risk is where most of the compliance work lives. A system is high-risk if it is a safety component of a product already regulated under EU law listed in Annex I, or if it falls within one of the areas in Annex III: biometrics, critical infrastructure, education and vocational training, employment and worker management, access to essential private and public services, law enforcement, migration and border control, and administration of justice and democratic processes.
For high-risk systems, the Act requires the provider — the actor that develops the system, or has it developed, and places it on the market under its own name — to build and maintain a defined set of controls before and after the system goes to market. These provider obligations (Articles 8 to 17 and related provisions) are the heart of the regime:
- A risk management system running across the full lifecycle of the AI system.
- Data and data governance — training, validation, and testing data managed for quality, representativeness, and bias.
- Technical documentation demonstrating conformity, kept up to date.
- Automatic record-keeping (logging) of events over the system's lifetime to enable traceability.
- Transparency and clear instructions for use so deployers can operate the system correctly.
- Human oversight designed into the system so people can understand, monitor, and intervene.
- Appropriate accuracy, robustness, and cybersecurity for the system's intended purpose.
- A quality management system, a conformity assessment, CE marking, and registration in the EU database before market entry, followed by post-market monitoring.
Providers vs deployers: who does what
The Act assigns different duties to different actors along the value chain. The two that matter most for in-scope organizations are the provider and the deployer, and the distinction is consequential: the provider carries the build-time obligations, while the deployer carries the use-time obligations. Importers and distributors sit in between and mainly verify that upstream conformity is in place.
A note on drift: an organization that materially modifies a high-risk system, or puts its own name on it, can itself become a provider and inherit the provider obligations. Mapping which role you occupy for each system is an early step in any readiness effort.
| Role | Definition | Main duties |
|---|---|---|
| Provider | Develops an AI system or general-purpose AI model, or has one developed, and places it on the market or puts it into service under its own name | Full high-risk obligations: risk management, data governance, documentation, logging, human oversight, accuracy and cybersecurity, quality management, conformity assessment, CE marking, registration, post-market monitoring |
| Deployer | Uses an AI system under its own authority in a professional capacity | Use the system per the provider's instructions, ensure human oversight, monitor operation, keep logs, inform affected workers and individuals, and — for certain deployers — carry out a fundamental rights impact assessment (Article 27) |
| Importer / distributor | Places on, or makes available on, the EU market an AI system from a provider established outside the EU | Verify that the required conformity assessment, documentation, and CE marking are in place before making the system available |
General-purpose AI models
The Act adds a distinct layer for general-purpose AI (GPAI) models — the foundation models that can be adapted to many downstream tasks. Providers of GPAI models have their own obligations, centered on technical documentation, information for downstream providers who build on the model, a policy to respect EU copyright law, and a published summary of the content used for training.
A subset of GPAI models are designated as carrying systemic risk, based on their capabilities. Providers of those models take on additional obligations, including model evaluation, systemic-risk assessment and mitigation, incident tracking and reporting, and cybersecurity protection. Governance of GPAI models is coordinated centrally by the AI Office rather than solely by national authorities.
The phased timeline
The Act's obligations switch on in stages counted from its entry into force on 1 August 2024. Reading the timeline correctly matters, because the date an obligation applies is the date it becomes enforceable — not a target you can slip. The main milestones set out in the Regulation are:
| Date | What starts to apply |
|---|---|
| 1 August 2024 | The Regulation enters into force; the countdown to each phase begins |
| 2 February 2025 | Prohibitions on unacceptable-risk practices (Article 5) and AI-literacy obligations apply |
| 2 August 2025 | Rules for general-purpose AI models, governance bodies, and penalties apply |
| 2 August 2026 | The bulk of the Act applies, including high-risk obligations for Annex III systems and transparency duties |
| 2 August 2027 | High-risk obligations for Annex I systems (AI as a safety component of regulated products) apply, completing the phase-in |
How to prepare
Preparation is less about a single deadline and more about knowing where each of your AI systems sits and building the evidence the Act expects. A practical starting sequence:
- Inventory your AI systems and, for each, determine your role — provider, deployer, importer, or distributor.
- Classify each system by tier; confirm none fall under the Article 5 prohibitions, and flag anything in Annex I or Annex III as high-risk.
- For high-risk systems, stand up the required artifacts: a lifecycle risk management process, data-governance records, technical documentation, event logging, and a documented human-oversight design.
- For deployers, confirm you can operate within the provider's instructions, keep logs, and — where required — complete a fundamental rights impact assessment.
- For GPAI models you provide or build on, prepare model documentation, downstream information, a copyright policy, and a training-content summary.
- Keep evidence traceable and current: the Act rewards records that show a control operated over time, not a one-time snapshot.
Frequently asked questions
Who does the EU AI Act apply to?
It applies to providers that place AI systems on the EU market or put them into service in the EU regardless of where they are established, to deployers of AI systems located in the EU, and to providers and deployers outside the EU where the system's output is used in the EU. Its reach is extraterritorial, so many non-EU organizations fall in scope.
When does the EU AI Act take effect?
It entered into force on 1 August 2024 and applies in phases. Prohibitions on unacceptable-risk practices applied from 2 February 2025; rules for general-purpose AI models and governance from 2 August 2025; most high-risk and transparency obligations from 2 August 2026; and high-risk obligations for systems that are safety components of regulated products from 2 August 2027.
What is the difference between a provider and a deployer?
A provider develops an AI system or has one developed and places it on the market under its own name; it carries the build-time obligations for high-risk systems. A deployer uses an AI system under its own authority in a professional capacity and carries use-time duties such as human oversight, monitoring, and logging. An organization that materially modifies a system, or rebrands it, can become a provider.
Does the EU AI Act replace the GDPR?
No. The AI Act adds AI-specific obligations that operate alongside existing EU law, including the GDPR and product-safety rules. Where an AI system processes personal data, both the AI Act and data-protection law can apply at the same time; the AI Act does not override or absorb the GDPR.
What are the penalties under the EU AI Act?
Article 99 sets maximum administrative fines. Breaching the Article 5 prohibitions can draw fines up to 35 million euro or 7% of total worldwide annual turnover, whichever is higher. Other breaches of obligations can draw up to 15 million euro or 3%, and supplying incorrect or misleading information up to 7.5 million euro or 1%.
Published by ShipReady Metrics, an evidence-based technology and compliance intelligence platform. This guide is educational and vendor-neutral.