Resource · EU AI Act
The EU AI Act, explained plainly
A practical guide for teams building or deploying AI in Europe. No legal jargon, no fear-mongering — just what you need to do, when, and how.
Prepared by EU AI Fit editorial team · Published 24 August 2026 · Source review 31 August 2026
What is the AI Act?
The EU AI Act (Regulation (EU) 2024/1689) is the world's first comprehensive horizontal law for artificial intelligence. It entered into force on 1 August 2024 and applies to any organisation that places AI systems on the EU market or uses them within the EU — regardless of where the organisation is based.
The Act uses a risk-based approach. Instead of regulating the technology itself, it regulates the use case. The more potential for harm, the more obligations apply.
If you deploy, develop, import, or distribute AI in the EU, this affects you. The penalties are significant: up to €35 million or 7% of global annual turnover for prohibited practices, and up to €15 million or 3% for other violations.
The four risk classes
Every AI system falls into one of these categories. Your obligations depend on which one applies.
Prohibited
Specific practices prohibited by Article 5, with narrow exceptions applying to certain law-enforcement uses.
- Social scoring by public authorities
- Untargeted facial image scraping
- Emotion recognition in workplaces and schools
High-risk
Systems that significantly affect health, safety, fundamental rights, or critical infrastructure. Full Article 8–17 obligations apply.
- Recruitment and CV-screening tools
- Credit scoring and insurance pricing
- Medical diagnosis aids
- Critical infrastructure management
Transparency risk
Systems and outputs subject to specific Article 50 transparency duties, which differ for providers and deployers.
- Chatbots and virtual assistants
- Deepfakes and synthetic media
- Emotion recognition systems
- Biometric categorisation systems
Minimal-risk
All other AI systems. No specific obligations under the AI Act, though existing GDPR and sectoral rules still apply.
- Spam filters
- Recommendation engines
- Inventory forecasting
- Search ranking
The compliance timeline
The AI Act is being phased in. Transparency duties now apply, while the principal high-risk dates are 2 December 2027 and 2 August 2028.
Original prohibited practices and AI literacy
The original Article 5 prohibitions and Article 4 duty to take measures supporting staff AI literacy began to apply.
GPAI transparency obligations
General-purpose AI model providers must comply with Article 53: technical documentation, downstream-provider information, copyright policy, and training-data summary.
Transparency rules apply
Article 50 disclosure duties apply to relevant chatbots, synthetic content, deepfakes, emotion-recognition systems, and biometric categorisation systems.
New synthetic intimate-content prohibitions
The additional Article 5 prohibitions introduced by Regulation (EU) 2026/1744 begin to apply, alongside the transition for certain pre-existing synthetic-content systems.
Annex III high-risk rules apply
High-risk rules apply to listed stand-alone use cases including biometrics, critical infrastructure, education, employment, essential services, migration, and justice.
Regulated-product high-risk rules apply
The extended date applies to high-risk AI systems embedded in regulated products covered by the product-safety legislation listed in Annex I.
High-risk obligations
Articles 8–15 set requirements that providers must ensure high-risk systems meet. Deployers have separate operational duties under Article 26, including following instructions, assigning competent human oversight, monitoring use, keeping relevant logs under their control, and responding when risks or incidents arise.
Risk management system
Establish, implement, document, and maintain a risk management system for the AI system's lifecycle.
Data governance
Ensure training, validation, and testing data are relevant, representative, and free of errors to the extent possible.
Technical documentation
Maintain technical documentation demonstrating conformity before market placement.
Record-keeping and logging
Implement automatic logging of events relevant for traceability and post-market monitoring.
Transparency to deployers
Provide instructions for use so deployers can interpret system output and exercise meaningful human oversight.
Human oversight
Design the system so it can be effectively overseen by natural persons during use.
Accuracy, robustness, cybersecurity
Achieve appropriate levels of accuracy, robustness, and cybersecurity throughout the lifecycle.
Post-market monitoring
Establish a system to monitor performance and serious incidents after the AI system has been placed on the market.
What about general-purpose AI models?
GPAI model providers (like OpenAI, Anthropic, Google) have their own set of obligations under Article 53–55. These include:
- Technical documentation for the model and its training process
- Information and documentation for downstream providers who integrate the model
- A policy to comply with EU copyright law (including the TDM opt-out)
- A publicly available summary of training data content
If you're a deployer using a GPAI model (e.g. you build a product on top of GPT-4 or Claude), your obligations depend on how the model is used. A high-risk use can create deployer duties under Article 26; separate provider duties may arise for the organisation that places the resulting AI system on the market or puts it into service under its own name.
Practical resources
Work through the Act by task
Use these focused guides to build an inventory, assess roles and exposure, and turn obligations into reviewable evidence.
EU AI Act compliance checklist for SMEs
A practical EU AI Act compliance checklist for SMEs and SaaS teams covering inventory, roles, risk, evidence, ownership and review.
Read guideAI system inventory template for EU AI Act readiness
Use an AI system inventory template covering purpose, provider, data, people, ownership and review fields needed for EU AI Act readiness.
Read guideEU AI Act provider vs deployer roles
Understand the practical difference between provider and deployer roles under the EU AI Act and why one company can hold different roles.
Read guideAnnex III high-risk AI systems explained
A practical guide to identifying potential Annex III high-risk AI use cases and documenting the facts needed for expert review.
Read guideArticle 50 disclosure template and checklist
Use a practical EU AI Act Article 50 disclosure checklist for AI interaction, synthetic content, deepfakes and biometric uses.
Read guideArticle 4 AI literacy: a practical plan
Create a proportionate EU AI Act Article 4 AI literacy programme based on staff roles, system risks and operational context.
Read guideEU AI Act evidence and documentation plan
Turn EU AI Act obligations into an evidence plan with owners, review dates, versions, approvals and secure storage choices.
Read guideDoes the EU AI Act apply to UK SaaS companies?
A practical scope guide for UK SaaS companies offering AI systems or services to EU customers and users.
Read guideEU AI Act deadlines: 2026 to 2028
A practical EU AI Act implementation timeline covering Article 50, high-risk systems, GPAI and regulated-product dates from 2026 to 2028.
Read guideEU AI Act FRIA template and readiness checklist
Prepare a Fundamental Rights Impact Assessment with a practical Article 27 applicability screen, evidence checklist and specialist-review boundary.
Read guideEU AI Act supplier assurance questionnaire
A practical AI supplier due-diligence questionnaire covering roles, models, data, security, transparency, oversight, incidents and change.
Read guideISO 42001 vs the EU AI Act
Understand how ISO/IEC 42001 AI management systems relate to EU AI Act roles, classifications, legal obligations and system evidence.
Read guideAI governance policy template for SMEs
Build an AI governance policy that connects accountable roles, approved use, inventory, risk, suppliers, incidents, training and evidence.
Read guideArticle 50 AI disclosure wording examples
Draft clear EU AI Act Article 50 disclosures for direct AI interaction, synthetic content and deepfakes, with an implementation evidence checklist.
Read guideEU AI Act deployer documentation pack
Organise the records an AI deployer may need across instructions, oversight, logs, monitoring, incidents, FRIA, privacy and worker information.
Read guidePrimary sources and review standard
Prepared by the EU AI Fit editorial team from the cited official sources. Regulatory statements are checked against the current consolidated text and European Commission material; product workflow guidance is checked against the current EU AI Fit release. This is not legal advice or certification. Read how we review and update guidance.
Ready to check your compliance?
Run the free exposure check to identify likely scope and risk indicators, then retain a deeper, system-specific assessment in the workspace.
Start the exposure check