Staff use an off-the-shelf copilot for drafts
Usually no special risk tier on those facts, but the organisation still needs contextual AI-literacy measures and must check privacy, confidentiality, copyright and output quality.
Baseline duties applyA support bot, applicant ranker, medical-device safety component and general-purpose model do not follow one checklist. Start with what the system does, where it reaches, which role you hold and when that route applies.
Operational guide, not legal advice. Legal position checked 2 August 2026. This page reads Regulation (EU) 2024/1689 together with Regulation (EU) 2026/1744, which entered into force on 27 July 2026.
The same model can sit in an ordinary drafting workflow, a prohibited practice, a high-risk decision system or several routes at once.
Usually no special risk tier on those facts, but the organisation still needs contextual AI-literacy measures and must check privacy, confidentiality, copyright and output quality.
Baseline duties applyRecruitment and candidate evaluation are Annex III use cases. Prepare the provider and deployer controls before the amended high-risk rules apply on 2 December 2027.
High-risk routeIf the Section A product route and third-party health-or-safety conformity trigger are met, it is Annex I high-risk. The corresponding AI Act rules apply from 2 August 2028.
Product high-risk routeThe interactive-system provider normally designs an AI notice into the first interaction. Article 50 applies from 2 August 2026.
Transparency routeModel documentation, downstream information, copyright policy and a public training-content summary are separate from the rules for an app built on that model.
GPAI routeDo not jump to disclosure. Screen the Article 5 prohibition first; the original prohibited-practice families have applied since 2 February 2025.
Stop and classifyA professional deployer may need a deepfake or text disclosure. Substantive review with an accountable publisher matters for the public-interest-text exception.
Article 50 routeThe system may be high-risk, the deployer may owe notice, and the affected person may have complaint and explanation routes. Other equality and data-protection rights continue to apply.
Rights and high-risk routesChoose every situation that fits. The result is a linked reading path, not a verdict that the system is lawful or compliant.
Every route remains available without the interactive pathfinder. Start with scope, roles and the prohibited-practice screen.
“AI” in marketing copy is not the test. The Act defines an AI system by how a machine-based system infers outputs that can influence physical or virtual environments.
AI system: a machine-based system designed to operate with varying autonomy, which may adapt after deployment and infers from inputs how to generate predictions, content, recommendations or decisions for explicit or implicit objectives.
The Act can reach non-EU providers placing systems or GPAI models on the EU market, EU deployers, and third-country providers or deployers whose system output is used in the EU.
AI systems or models specifically developed and put into service solely for scientific R&D, and research, testing or development activity before market placement or putting into service, can be excluded. Other systems merely used in research remain covered; real-world testing is regulated, not generally excluded.
A natural person’s purely personal, non-professional use is excluded from deployer obligations. It does not legalise fraud, harassment, privacy violations or unlawful content.
The system-level exemption does not cover Article 5, Article 50 or high-risk systems. GPAI models have a separate, narrower open-source treatment.
GDPR, ePrivacy, equality, employment, copyright, consumer, product-safety, sector and national law continue alongside the AI Act.
Simple deterministic rules may fall outside the definition; sophisticated optimisation or learned prediction may not. Record the architecture, inputs, outputs, autonomy and inference method.
One organisation can be provider, deployer and product manufacturer at the same time. Put the role in the system register instead of assuming the vendor owns every duty.
Develops or commissions a system or GPAI model and places it on the market or puts the system into service under its name, whether paid or free.
Uses an AI system under its authority for professional or organisational activity. Employees acting under the organisation’s instructions are normally part of that deployment.
An importer brings a third-country provider’s branded system to the EU market; a distributor makes a system available elsewhere in the supply chain.
Places a product on the market or into service with an AI system under its own name. Product-law and AI Act routes can meet in one conformity process.
An EU-established representative accepts a written mandate for a non-EU provider and performs the specified documentation, cooperation and contact duties.
A person in the EU may receive notices and can use complaint or explanation routes. “Affected person” is not an operator role, but it changes the control design.
Role-transfer trap: an importer, distributor, deployer or other third party can become the provider by putting its name on the system, substantially modifying it, or changing the intended purpose so that it becomes high-risk. Contract for documentation and technical access before that happens.
General duties, other law and voluntary controls sit underneath the special risk routes.
Tailor measures to people’s knowledge, experience, training, use context and affected groups. The amended rule does not require one certificate or guarantee a fixed level for every person.
High-risk providers may exceptionally process special-category personal data where strictly necessary for Article 10 bias detection and correction. Providers and deployers of other AI systems or models, and deployers of high-risk systems, may do so only for biases likely to affect health or safety, harm fundamental rights or cause discrimination prohibited by Union law, and only with every Article 4a safeguard. This creates no duty to conduct bias work.
For systems outside high-risk rules, voluntary codes can still cover environmental performance, accessibility, inclusion, risk testing and governance. Other binding law may demand the same controls independently.
Check from the top down. A high-risk system can also have Article 50 duties, and an application can inherit obligations from a GPAI model without becoming the model provider.
Eight original practice families have applied since 2 February 2025. Two enacted additions apply from 2 December 2026; other law may already prohibit the same conduct.
Subliminal, purposefully manipulative or deceptive techniques that materially distort an informed decision and cause, or are reasonably likely to cause, significant harm.
Using age, disability or a specific social or economic situation to materially distort behaviour in a significantly harmful way.
Scoring people over time from social behaviour or personal characteristics where detrimental treatment is unrelated, unjustified or disproportionate.
Assessing or predicting criminal-offence risk based solely on profiling or personality traits, subject to the narrow objective-facts and human-assessment boundary.
Creating or expanding facial-recognition databases by indiscriminately scraping the internet or CCTV footage.
Inferring emotions in workplaces or education institutions, except for a use intended for medical or safety reasons.
Using biometric data to infer race, political opinions, trade-union membership, religion, philosophical beliefs, sex life or sexual orientation, subject to narrow statutory boundaries.
Law-enforcement use in publicly accessible spaces, except tightly limited victim, imminent-threat and serious-offence cases with legal, necessity, proportionality and authorisation safeguards.
Realistic intimate or sexually explicit material of an identifiable person without the specified explicit consent. The amendment defines when provider and deployer conduct is caught and how safeguards matter.
AI systems used or designed for generation or manipulation of covered material, subject to the amendment’s purpose, foreseeability, safeguard and “without right” provisions.
The enacted 2026 amendment moved Annex III duties to 2 December 2027 and Annex I product duties to 2 August 2028. Those are application dates, not permission to ignore applicable sector, data or equality law.
AI is a safety component of, or is itself, a product listed in Annex I and the product must undergo third-party conformity assessment for health or safety risks under that product law. Non-safety convenience or efficiency functions are excluded unless failure could endanger health or safety. Section A products take the direct Chapter III route, subject to any Article 2(13) delegated limitation; for Section B products, Article 2(2) routes most requirements through sector law.
Applies 2 August 2028The intended use falls within a specific Annex III case in biometrics, infrastructure, education, employment, essential services, law enforcement, migration, justice or democratic processes.
Applies 2 December 2027An Annex III system may be found not high-risk only where it does not pose a significant risk of harm to health, safety or fundamental rights—including by not materially influencing a decision outcome—and performs at least one listed narrow procedural, preparatory, completed-work or pattern-detection task. Profiling of natural persons remains high-risk. Document and register the finding.
Document and registerDo not flatten Annex I: for Section B products, Article 2(2) directly retains only Article 6(1), Article 60a and Articles 102–112; Articles 57–59 follow only as sector law integrates the high-risk requirements. For Section A, Article 2(13) permits delegated limits on duplicated duties where product law provides equal or greater protection. Verify any applicable delegated act rather than assuming those duties are switched off.
Supply-chain control: importers and distributors verify provider, conformity, documentation, marking and storage or transport duties before making a high-risk system available. A rebrand, substantial modification or changed high-risk purpose can transfer provider responsibility.
Legacy high-risk transition: apart from specified large-scale Union IT systems, Article 111 generally brings a high-risk system placed on the market or put into service before its relevant Chapter III date into the Regulation only if its design is significantly changed from that date. High-risk systems intended for public-authority use must comply by 2 August 2030 in any case. Article 5 remains unaffected.
Calling a model through an API does not make every customer its provider. Training, adapting, releasing and integrating a model can create different roles along the value chain.
A model is presumed to have high-impact capabilities above 1025 training FLOPs, or can be designated on equivalent capability or impact. Notify the Commission within two weeks after the threshold is met or known, subject to the rebuttal process.
Qualifying free and open-source GPAI models can be exempt from some technical and downstream documentation and representative duties. Copyright policy and training-summary duties remain, and systemic-risk models do not receive the same exemption.
Chapter V obligations apply to providers placing covered models on the EU market from that date.
The AI Office can enforce Chapter V and the GPAI fine regime. Code adherence is voluntary, not immunity.
Providers of models placed on the market before 2 August 2025 must bring them into compliance.
Each card names a different actor and trigger. A disclosure never makes a prohibited, unsafe or otherwise unlawful system lawful.
Providers design systems for direct human interaction so people are told they are interacting with AI by the first interaction, unless that fact is genuinely obvious in context.
Providers of systems generating synthetic text, audio, images or video make outputs marked and detectable using effective, interoperable, robust and reliable technical solutions as far as feasible.
Deployers inform people exposed to emotion-recognition or biometric-categorisation systems and comply with applicable personal-data law. Check Article 5 first because some uses are prohibited.
Deployers disclose AI-generated or manipulated media that resembles existing people, objects, places, entities or events and could falsely appear authentic or truthful. Evident creative works receive a less disruptive disclosure accommodation, not silence.
Deployers disclose AI-generated or manipulated text published to inform the public on matters of public interest, unless it receives qualifying human review or editorial control and a person or entity holds editorial responsibility.
For the public-interest-text exception, a competent person reviews meaning, facts and completeness, can change or reject the text, approves the final published version and sits inside a process with identifiable editorial responsibility.
Meaning, accuracy and completeness—not only spelling or style.
Verify factual claims and correct unsupported content.
Approve, change or reject the substance.
Prevent unreviewed AI changes after approval.
The Act does not mandate one sentence. Make the information clear, distinguishable, accessible and available no later than the first interaction or exposure.
You are chatting with an AI assistant.
This call is handled by an AI voice assistant.
This video contains AI-generated or AI-manipulated people or events.
This article was generated or altered with AI and has not received substantive human editorial review.
The Commission makes three human-visible labels freely reusable without attribution. They support Article 50(4) disclosure; they are not the provider-side machine-readable marking required by Article 50(2).
Use with a nearby plain-language label or accessible second layer that explains what AI did.
Use when the entire in-scope item was generated by AI, apart from prompting, with no human-created elements or qualifying editorial control.
Use when pre-existing human-made content was changed with AI into an in-scope deepfake or public-interest text.
Visible label ≠ machine-readable watermark. For Code signatories, provider-side marking uses signed metadata and, where applicable, an imperceptible watermark; there is no single universal Article 50(2) watermark file. These symbols are the human-perceptible disclosure layer. Non-signatories may use them, but must not imply that they signed the Code.
The AI Act does not create one universal right to a model explanation or compensation. It creates specific notices and remedies while other EU and national rights continue.
Where an Annex III high-risk system makes or assists decisions about people, the deployer informs them that they are subject to its use, subject to the Act’s scope and dates.
A person subject to a deployer decision based on output from an Annex III high-risk system—excluding point 2 critical-infrastructure systems—can obtain a clear, meaningful explanation of the system’s role and the main decision elements where the decision has legal or similarly significant effects which they consider adverse to health, safety or fundamental rights. Statutory and parallel-Union-law limits apply.
Any natural or legal person with grounds to suspect an infringement can complain to the relevant market-surveillance authority.
EU whistleblower protections apply to reporting AI Act infringements. Downstream GPAI providers also have a specific complaint route to the AI Office.
Access, information, objection, human intervention, non-discrimination and judicial remedies may arise under other law even where the AI Act route is unavailable.
Give the affected person a decision owner, channel, response process, evidence-preservation rule and escalation path—not only a generic privacy inbox.
Sandboxes can improve legal certainty and evidence. They do not waive Article 5, data law, safeguards or liability for harm.
Each Member State must have at least one national or jointly equivalent sandbox operational by 2 August 2027. The AI Office may establish a Union-level sandbox within its competence; the EDPS may do so for Union bodies.
Covered high-risk testing outside a sandbox needs a plan, authority route, registration and oversight. Informed consent, reversibility, incident handling, time limits and data safeguards apply subject to precise exceptions.
Market-surveillance authorities enforce most system duties; notifying authorities oversee conformity-assessment bodies. Member States provide a single contact point.
The Commission, acting through the AI Office, exclusively enforces Chapter V and the specified Article 75(1) system categories, including same-undertaking GPAI-based systems and VLOP/VLOSE systems, subject to statutory sector and public-authority exceptions. This system competence reaches deployers only where they are also the provider or belong to the same undertaking; other deployers remain under national supervision.
The European AI Board coordinates national application. The Scientific Panel and Advisory Forum add technical and stakeholder expertise.
The EDPS supervises Union institutions. Designated notified bodies perform the third-party conformity work required for covered high-risk systems.
Sandbox safe harbour has limits: participants remain liable under applicable Union and national law for damage to third parties. Prospective providers who follow the sandbox plan and terms and act in good faith on competent-authority guidance are protected from AI Act administrative fines for sandbox infringements, but supervisory and corrective powers remain.
The Act entered into force on 1 August 2024. The timeline below reflects the enacted July 2026 amendment, not the earlier proposal.
General provisions and Article 50 apply; GPAI enforcement is active. Annex III and Annex I high-risk lifecycle duties remain on the later dates enacted below.
Regulation (EU) 2024/1689 enters into force, with phased application.
Chapters I and II apply, including Article 4 and the eight original Article 5 practice families.
Chapter III Section 4, Chapter V, Chapter VII, Chapter XII and Article 78 apply, except Article 101; providers of GPAI models placed before this date retain the 2 August 2027 transition.
Regulation (EU) 2026/1744 enacts the revised dates and targeted changes; amended Articles 102–110 also apply from this date.
Most remaining provisions, Article 50 duties and Commission GPAI enforcement apply.
The intimate-depiction and CSAM prohibitions apply. Providers of synthetic audio, image, video or text systems, including GPAI systems, placed on the market before 2 August 2026 must comply with Article 50(2)’s machine-readable marking duty by this date; the other Article 50 duties already apply from 2 August 2026.
National sandboxes must be operational; pre-2 August 2025 GPAI models must comply.
Chapter III Sections 1–3, except Article 6(5), apply to Article 6(2) listed-use systems, subject to Article 111’s legacy-system transition.
Chapter III Sections 1–3, except Article 6(5), apply to Article 6(1) systems, subject to Section B sector-law treatment, Article 2(13) delegated limitations and Article 111’s legacy-system transition.
Providers and deployers of pre-existing high-risk systems intended for use by public authorities must comply by this date. AI components of Annex X large-scale IT systems placed on the market or put into service before 2 August 2027 must comply by 31 December 2030.
Whichever ceiling is higher for an undertaking, subject to proportionality and the special SME treatment.
Covers the specified duties in Articles 16, 22–26, 31, 33, 34 and 50, including the amended Article 25(2) and (4) value-chain cooperation duties.
For incorrect, incomplete or misleading information supplied to a notified body or competent authority in reply to a request.
A separate Article 101 ceiling for intentional or negligent Chapter V and enforcement failures: whichever is higher for an undertaking.
AI Office operator enforcement: for Article 75(1) operators, Article 75c can apply the €15m/3% band to any applicable AI Act infringement, even one not enumerated in Article 99(4), and to failures to comply with enforcement decisions, measures or binding commitments. Misleading replies use the €7.5m/1% band. Periodic payments can reach 5% of average daily income or worldwide annual turnover in the preceding financial year per day.
Union institutions have separate ceilings: Article 100 allows the EDPS to impose up to €1.5m for Article 5 infringements and up to €750,000 for other infringements.
Do not build separate spreadsheets for labels, literacy, GPAI and high-risk projects. Keep one source of truth and attach the evidence each route requires.
| Register field | Record | Acceptance check |
|---|---|---|
| System and purpose | Owner, version, model, inputs, outputs, users, affected groups and intended purpose | Describes the actual workflow, not “AI-powered” |
| Scope and EU link | AI-system or GPAI rationale, market, establishment, output use and any exclusion | Every exclusion cites facts and a legal basis |
| Roles and supply chain | Provider, deployer, importer, distributor, manufacturer, representative and affected people | Contracts provide required documents and technical access |
| Route classification | Article 5 screen, Annex I/III test, GPAI layer, Article 50 triggers and other law | Concurrent routes remain visible |
| Date and owner | Applicable date, transition, accountable role and decision authority | No bare “2026 deadline” or other relative-date language |
| Controls and evidence | Literacy, data, testing, oversight, notices, conformity, review, logs and approvals | Each control has an artefact and a pass condition |
| Monitoring and change | Incidents, complaints, performance, model or purpose changes and review date | A trigger reopens classification before release |
Include shadow use, vendor features, embedded product AI and retired versions still affecting people.
No release until scope, role, prohibition, route, date and control owner are recorded.
New purpose, model, audience, data, autonomy, integration or brand can change risk and role.
Guidance and codes explain implementation but do not replace the Regulation. Check EUR-Lex for a consolidated text; where it does not yet include the amendment, read both Regulations together.
Classify the situation. Follow every route it triggers.