Build · EU AI Act · Regulation plus enacted 2026 amendment

The EU AI Act is more than labels.

A support bot, applicant ranker, medical-device safety component and general-purpose model do not follow one checklist. Start with what the system does, where it reaches, which role you hold and when that route applies.

Operational guide, not legal advice. Legal position checked 2 August 2026. This page reads Regulation (EU) 2024/1689 together with Regulation (EU) 2026/1744, which entered into force on 27 July 2026.

5routes can stackPROHIBITED · HIGH-RISK · GPAI · TRANSPARENCY · OTHER
6+roles can carry dutiesPROVIDER ≠ DEPLOYER ≠ SUPPLY CHAIN
2024→30phased legal timelineENTRY INTO FORCE ≠ APPLICATION DATE
01 · Situation first

Start with the situation, not the tool.

The same model can sit in an ordinary drafting workflow, a prohibited practice, a high-risk decision system or several routes at once.

Internal assistant

Staff use an off-the-shelf copilot for drafts

Usually no special risk tier on those facts, but the organisation still needs contextual AI-literacy measures and must check privacy, confidentiality, copyright and output quality.

Baseline duties apply
Employment

Software ranks job applicants

Recruitment and candidate evaluation are Annex III use cases. Prepare the provider and deployer controls before the amended high-risk rules apply on 2 December 2027.

High-risk route
Regulated product

AI performs a medical-device safety function

If the Section A product route and third-party health-or-safety conformity trigger are met, it is Annex I high-risk. The corresponding AI Act rules apply from 2 August 2028.

Product high-risk route
Human interaction

A customer talks to a support bot

The interactive-system provider normally designs an AI notice into the first interaction. Article 50 applies from 2 August 2026.

Transparency route
Model release

A company trains and releases a GPAI model

Model documentation, downstream information, copyright policy and a public training-content summary are separate from the rules for an app built on that model.

GPAI route
Harmful practice

AI manipulates vulnerable people or creates social scores

Do not jump to disclosure. Screen the Article 5 prohibition first; the original prohibited-practice families have applied since 2 February 2025.

Stop and classify
Synthetic media

A realistic CEO video or public-interest article is generated

A professional deployer may need a deepfake or text disclosure. Substantive review with an accountable publisher matters for the public-interest-text exception.

Article 50 route
Affected person

AI materially influences a benefit, credit or other decision

The system may be high-risk, the deployer may owe notice, and the affected person may have complaint and explanation routes. Other equality and data-protection rights continue to apply.

Rights and high-risk routes

Binding baselineThe Act is a set of stackable duties, not one risk score. Read Regulation (EU) 2024/1689 together with the enacted Regulation (EU) 2026/1744.

02 · Act-wide pathfinder

Find the routes worth opening.

Choose every situation that fits. The result is a linked reading path, not a verdict that the system is lawful or compliant.

Every route remains available without the interactive pathfinder. Start with scope, roles and the prohibited-practice screen.

03 · Scope

First ask whether the Act reaches the system.

“AI” in marketing copy is not the test. The Act defines an AI system by how a machine-based system infers outputs that can influence physical or virtual environments.

AI system: a machine-based system designed to operate with varying autonomy, which may adapt after deployment and infers from inputs how to generate predictions, content, recommendations or decisions for explicit or implicit objectives.

EU reach

Market, establishment or output

The Act can reach non-EU providers placing systems or GPAI models on the EU market, EU deployers, and third-country providers or deployers whose system output is used in the EU.

Narrow exclusions

Purpose and phase matter

AI systems or models specifically developed and put into service solely for scientific R&D, and research, testing or development activity before market placement or putting into service, can be excluded. Other systems merely used in research remain covered; real-world testing is regulated, not generally excluded.

Personal use

Only deployer duties drop out

A natural person’s purely personal, non-professional use is excluded from deployer obligations. It does not legalise fraud, harassment, privacy violations or unlawful content.

Open source

Not a blanket exemption

The system-level exemption does not cover Article 5, Article 50 or high-risk systems. GPAI models have a separate, narrower open-source treatment.

Not an island

Other law continues

GDPR, ePrivacy, equality, employment, copyright, consumer, product-safety, sector and national law continue alongside the AI Act.

Borderline software

Document the inference test

Simple deterministic rules may fall outside the definition; sophisticated optimisation or learned prediction may not. Record the architecture, inputs, outputs, autonomy and inference method.

Official classification helpUse Articles 2 and 3 of the binding Act and the Commission’s non-binding AI-system definition guidelines.

04 · Actors

Assign the role before the obligation.

One organisation can be provider, deployer and product manufacturer at the same time. Put the role in the system register instead of assuming the vendor owns every duty.

Provider

Develops or commissions a system or GPAI model and places it on the market or puts the system into service under its name, whether paid or free.

Deployer

Uses an AI system under its authority for professional or organisational activity. Employees acting under the organisation’s instructions are normally part of that deployment.

Importer and distributor

An importer brings a third-country provider’s branded system to the EU market; a distributor makes a system available elsewhere in the supply chain.

Product manufacturer

Places a product on the market or into service with an AI system under its own name. Product-law and AI Act routes can meet in one conformity process.

Authorised representative

An EU-established representative accepts a written mandate for a non-EU provider and performs the specified documentation, cooperation and contact duties.

Affected person

A person in the EU may receive notices and can use complaint or explanation routes. “Affected person” is not an operator role, but it changes the control design.

Role-transfer trap: an importer, distributor, deployer or other third party can become the provider by putting its name on the system, substantially modifying it, or changing the intended purpose so that it becomes high-risk. Contract for documentation and technical access before that happens.

05 · Horizontal duties

“Minimal risk” does not mean “nothing applies.”

General duties, other law and voluntary controls sit underneath the special risk routes.

Article 4 · applies since 2 February 2025

Support practical AI literacy

Tailor measures to people’s knowledge, experience, training, use context and affected groups. The amended rule does not require one certificate or guarantee a fixed level for every person.

  • Map roles, systems and foreseeable mistakes.
  • Teach limits, escalation, data handling and review controls.
  • Keep the materials, audience, date and refresh trigger.
Article 4a · strict permission

Bias work does not waive data law

High-risk providers may exceptionally process special-category personal data where strictly necessary for Article 10 bias detection and correction. Providers and deployers of other AI systems or models, and deployers of high-risk systems, may do so only for biases likely to affect health or safety, harm fundamental rights or cause discrimination prohibited by Union law, and only with every Article 4a safeguard. This creates no duty to conduct bias work.

  • Show why anonymised, synthetic or other data cannot work.
  • Restrict access, reuse, sharing and retention.
  • Document necessity, security and deletion.
Voluntary layer

Scale controls to the real risk

For systems outside high-risk rules, voluntary codes can still cover environmental performance, accessibility, inclusion, risk testing and governance. Other binding law may demand the same controls independently.

  • Set a named owner and acceptable-use boundary.
  • Measure quality, harm, cost and incident signals.
  • Reclassify after purpose, model or audience changes.

Amended literacy ruleThe 2026 amendment changed “ensure a sufficient level” to taking measures that support development. The obligation remains. See the Commission’s AI-literacy Q&A and Article 4 as amended by Regulation (EU) 2026/1744.

07 · Article 5

Stop prohibited practices before designing controls.

Eight original practice families have applied since 2 February 2025. Two enacted additions apply from 2 December 2026; other law may already prohibit the same conduct.

  1. Harmful manipulation or deception

    Subliminal, purposefully manipulative or deceptive techniques that materially distort an informed decision and cause, or are reasonably likely to cause, significant harm.

  2. Exploiting vulnerability

    Using age, disability or a specific social or economic situation to materially distort behaviour in a significantly harmful way.

  3. Social scoring

    Scoring people over time from social behaviour or personal characteristics where detrimental treatment is unrelated, unjustified or disproportionate.

  4. Individual criminal prediction

    Assessing or predicting criminal-offence risk based solely on profiling or personality traits, subject to the narrow objective-facts and human-assessment boundary.

  5. Untargeted facial-image scraping

    Creating or expanding facial-recognition databases by indiscriminately scraping the internet or CCTV footage.

  6. Emotion inference at work or school

    Inferring emotions in workplaces or education institutions, except for a use intended for medical or safety reasons.

  7. Sensitive biometric categorisation

    Using biometric data to infer race, political opinions, trade-union membership, religion, philosophical beliefs, sex life or sexual orientation, subject to narrow statutory boundaries.

  8. Real-time remote biometric identification

    Law-enforcement use in publicly accessible spaces, except tightly limited victim, imminent-threat and serious-offence cases with legal, necessity, proportionality and authorisation safeguards.

Enacted · applies 2 December 2026

Non-consensual intimate depictions

Realistic intimate or sexually explicit material of an identifiable person without the specified explicit consent. The amendment defines when provider and deployer conduct is caught and how safeguards matter.

Enacted · applies 2 December 2026

Child sexual abuse material

AI systems used or designed for generation or manipulation of covered material, subject to the amendment’s purpose, foreseeability, safeguard and “without right” provisions.

Do not reduce Article 5 to keywordsPurpose, effect, harm, context and exceptions are part of the legal test. Read Article 5, the 2026 additions and the Commission’s non-binding prohibition guidelines.

08 · Chapter III

High-risk depends on product and intended use.

The enacted 2026 amendment moved Annex III duties to 2 December 2027 and Annex I product duties to 2 August 2028. Those are application dates, not permission to ignore applicable sector, data or equality law.

Article 6(1) · Annex I

Regulated-product route

AI is a safety component of, or is itself, a product listed in Annex I and the product must undergo third-party conformity assessment for health or safety risks under that product law. Non-safety convenience or efficiency functions are excluded unless failure could endanger health or safety. Section A products take the direct Chapter III route, subject to any Article 2(13) delegated limitation; for Section B products, Article 2(2) routes most requirements through sector law.

Applies 2 August 2028
Article 6(2) · Annex III

Listed-use route

The intended use falls within a specific Annex III case in biometrics, infrastructure, education, employment, essential services, law enforcement, migration, justice or democratic processes.

Applies 2 December 2027
Article 6(3)

Narrow non-high-risk finding

An Annex III system may be found not high-risk only where it does not pose a significant risk of harm to health, safety or fundamental rights—including by not materially influencing a decision outcome—and performs at least one listed narrow procedural, preparatory, completed-work or pattern-detection task. Profiling of natural persons remains high-risk. Document and register the finding.

Document and register
BiometricsCritical infrastructureEducation and trainingEmployment and workersEssential services and benefitsLaw enforcementMigration and bordersJustice and democracy
Provider · where Chapter III duties apply

Prove the system across its lifecycle

  • Continuous risk management and pre-market testing.
  • Data governance where training, validation or test data are used.
  • Technical documentation, automatic logs and instructions.
  • Human-oversight design, accuracy, robustness and cybersecurity.
  • Quality management, conformity assessment, declaration, CE marking and registration.
  • Post-market monitoring, corrective action and serious-incident reporting.
Deployer · where Chapter III duties apply

Control the real use

  • Follow instructions and assign competent, trained, authorised oversight.
  • Keep controlled input data relevant and representative.
  • Monitor, suspend and report risks or serious incidents.
  • Retain controlled logs for at least six months unless other law says otherwise.
  • Give workplace and affected-person notices where required.
  • Complete registration, DPIA and fundamental-rights impact work where applicable.

Do not flatten Annex I: for Section B products, Article 2(2) directly retains only Article 6(1), Article 60a and Articles 102–112; Articles 57–59 follow only as sector law integrates the high-risk requirements. For Section A, Article 2(13) permits delegated limits on duplicated duties where product law provides equal or greater protection. Verify any applicable delegated act rather than assuming those duties are switched off.

Supply-chain control: importers and distributors verify provider, conformity, documentation, marking and storage or transport duties before making a high-risk system available. A rebrand, substantial modification or changed high-risk purpose can transfer provider responsibility.

Legacy high-risk transition: apart from specified large-scale Union IT systems, Article 111 generally brings a high-risk system placed on the market or put into service before its relevant Chapter III date into the Regulation only if its design is significantly changed from that date. High-risk systems intended for public-authority use must comply by 2 August 2030 in any case. Article 5 remains unaffected.

Classification is still factualUse Article 6, Annexes I and III and the Commission’s high-risk overview. On 2 August 2026, its detailed classification guidelines remained draft guidance, not binding law.

09 · Chapter V

A GPAI model is a separate compliance layer.

Calling a model through an API does not make every customer its provider. Training, adapting, releasing and integrating a model can create different roles along the value chain.

All GPAI providers

Document and enable downstream compliance

  • Maintain model technical documentation.
  • Give downstream system providers capability, limitation and integration information.
  • Maintain a policy for EU copyright and rights reservations.
  • Publish the required training-content summary using the AI Office template.
  • Appoint an EU representative when required and cooperate with authorities.
Systemic-risk GPAI

Add evaluation, mitigation and security

A model is presumed to have high-impact capabilities above 1025 training FLOPs, or can be designated on equivalent capability or impact. Notify the Commission within two weeks after the threshold is met or known, subject to the rebuttal process.

  • State-of-the-art evaluations and adversarial testing.
  • Union-level systemic-risk assessment and mitigation.
  • Serious-incident tracking and reporting.
  • Model and physical-infrastructure cybersecurity.
Open source

The exception is limited

Qualifying free and open-source GPAI models can be exempt from some technical and downstream documentation and representative duties. Copyright policy and training-summary duties remain, and systemic-risk models do not receive the same exemption.

Since 2 August 2025

New GPAI models

Chapter V obligations apply to providers placing covered models on the EU market from that date.

From 2 August 2026

Commission enforcement

The AI Office can enforce Chapter V and the GPAI fine regime. Code adherence is voluntary, not immunity.

By 2 August 2027

Legacy GPAI models

Providers of models placed on the market before 2 August 2025 must bring them into compliance.

Implementation routeUse the Commission’s GPAI provider guidelines, obligation summary, mandatory training-content template and the voluntary GPAI Code of Practice.

10 · Article 50 · applies from 2 August 2026

Transparency is one chapter, not the whole Act.

Each card names a different actor and trigger. A disclosure never makes a prohibited, unsafe or otherwise unlawful system lawful.

Article 50(1)

Interactive AI systems

Providers design systems for direct human interaction so people are told they are interacting with AI by the first interaction, unless that fact is genuinely obvious in context.

Actor
Provider
Keep
First-screen, message or audio capture; wording; context; version; accessibility test.
Article 50(2)

Machine-readable synthetic-output marking

Providers of systems generating synthetic text, audio, images or video make outputs marked and detectable using effective, interoperable, robust and reliable technical solutions as far as feasible.

Actor
Provider, including covered GPAI systems
Boundary
Standard editing, non-substantial alteration and narrow law-enforcement cases.
Article 50(3)

Emotion and biometric exposure

Deployers inform people exposed to emotion-recognition or biometric-categorisation systems and comply with applicable personal-data law. Check Article 5 first because some uses are prohibited.

Actor
Deployer
Keep
Exposure map, notice, purpose, legal assessment, data-protection record and complaint route.
Article 50(4)

Deepfake image, audio and video

Deployers disclose AI-generated or manipulated media that resembles existing people, objects, places, entities or events and could falsely appear authentic or truthful. Evident creative works receive a less disruptive disclosure accommodation, not silence.

Actor
Professional deployer
Keep
Authenticity assessment, expected audience, labelled final asset and placement.
Article 50(4)

Public-interest text

Deployers disclose AI-generated or manipulated text published to inform the public on matters of public interest, unless it receives qualifying human review or editorial control and a person or entity holds editorial responsibility.

Actor
Professional deployer
Keep
Public-interest decision, sources, substantive changes, final approval and accountable publisher.
Human review

“Someone looked at it” is not enough.

For the public-interest-text exception, a competent person reviews meaning, facts and completeness, can change or reject the text, approves the final published version and sits inside a process with identifiable editorial responsibility.

Examine substance

Meaning, accuracy and completeness—not only spelling or style.

Check sources

Verify factual claims and correct unsupported content.

Exercise authority

Approve, change or reject the substance.

Lock the final

Prevent unreviewed AI changes after approval.

Clear wording

Say what happened at first contact.

The Act does not mandate one sentence. Make the information clear, distinguishable, accessible and available no later than the first interaction or exposure.

Chat

You are chatting with an AI assistant.

Voice

This call is handled by an AI voice assistant.

Deepfake

This video contains AI-generated or AI-manipulated people or events.

Public-interest text

This article was generated or altered with AI and has not received substantive human editorial review.

Official EU labels · optional

Use the symbols as labels—not as a compliance stamp.

The Commission makes three human-visible labels freely reusable without attribution. They support Article 50(4) disclosure; they are not the provider-side machine-readable marking required by Article 50(2).

Official EU label: AI generated
Fully AI-generated

AI generated

Use when the entire in-scope item was generated by AI, apart from prompting, with no human-created elements or qualifying editorial control.

Official EU label: AI modified
Partially AI-modified

AI modified

Use when pre-existing human-made content was changed with AI into an in-scope deepfake or public-interest text.

Visible label ≠ machine-readable watermark. For Code signatories, provider-side marking uses signed metadata and, where applicable, an imperceptible watermark; there is no single universal Article 50(2) watermark file. These symbols are the human-perceptible disclosure layer. Non-signatories may use them, but must not imply that they signed the Code.

Final non-binding guidance on binding lawThe Commission’s final Article 50 guidelines explain the binding rule. The transparency Code is voluntary, and use of the official icon set alone is neither proof of compliance nor proof of Code membership.

11 · Rights and remedies

Design the route back to a responsible human.

The AI Act does not create one universal right to a model explanation or compensation. It creates specific notices and remedies while other EU and national rights continue.

Article 26(11) · from 2 December 2027

Notice of high-risk decision support

Where an Annex III high-risk system makes or assists decisions about people, the deployer informs them that they are subject to its use, subject to the Act’s scope and dates.

Article 86 · applies from 2 August 2026

Meaningful explanation

A person subject to a deployer decision based on output from an Annex III high-risk system—excluding point 2 critical-infrastructure systems—can obtain a clear, meaningful explanation of the system’s role and the main decision elements where the decision has legal or similarly significant effects which they consider adverse to health, safety or fundamental rights. Statutory and parallel-Union-law limits apply.

Article 85 · applies from 2 August 2026

Complaint to the authority

Any natural or legal person with grounds to suspect an infringement can complain to the relevant market-surveillance authority.

Article 87 · applies from 2 August 2026

Protected reporting

EU whistleblower protections apply to reporting AI Act infringements. Downstream GPAI providers also have a specific complaint route to the AI Office.

Parallel rights

GDPR and equality law remain

Access, information, objection, human intervention, non-discrimination and judicial remedies may arise under other law even where the AI Act route is unavailable.

Practical control

Make contact findable

Give the affected person a decision owner, channel, response process, evidence-preservation rule and escalation path—not only a generic privacy inbox.

Remedy boundaryArticles 85–87 create complaint, explanation and reporting routes. The AI Act itself does not turn every breach into a criminal offence or guarantee compensation; other Union and national remedies may apply.

12 · Innovation and governance

Test under supervision, then keep owning the risk.

Sandboxes can improve legal certainty and evidence. They do not waive Article 5, data law, safeguards or liability for harm.

Regulatory sandboxes

Controlled, time-limited development

Each Member State must have at least one national or jointly equivalent sandbox operational by 2 August 2027. The AI Office may establish a Union-level sandbox within its competence; the EDPS may do so for Union bodies.

  • Agree a sandbox plan, scope, safeguards and supervision.
  • Use written proof and exit reports as compliance evidence—not certification.
  • Mitigate significant risks or expect testing to be suspended.
Real-world testing

People are not an ungoverned test set

Covered high-risk testing outside a sandbox needs a plan, authority route, registration and oversight. Informed consent, reversibility, incident handling, time limits and data safeguards apply subject to precise exceptions.

  • Separate laboratory validation from regulated real-world testing.
  • Preserve consent, approvals, versions, incidents and outcomes.
  • Keep a prompt recall, suspension and deletion process.

National authorities

Market-surveillance authorities enforce most system duties; notifying authorities oversee conformity-assessment bodies. Member States provide a single contact point.

European AI Office

The Commission, acting through the AI Office, exclusively enforces Chapter V and the specified Article 75(1) system categories, including same-undertaking GPAI-based systems and VLOP/VLOSE systems, subject to statutory sector and public-authority exceptions. This system competence reaches deployers only where they are also the provider or belong to the same undertaking; other deployers remain under national supervision.

AI Board and expert bodies

The European AI Board coordinates national application. The Scientific Panel and Advisory Forum add technical and stakeholder expertise.

EDPS and notified bodies

The EDPS supervises Union institutions. Designated notified bodies perform the third-party conformity work required for covered high-risk systems.

Sandbox safe harbour has limits: participants remain liable under applicable Union and national law for damage to third parties. Prospective providers who follow the sandbox plan and terms and act in good faith on competent-authority guidance are protected from AI Act administrative fines for sandbox infringements, but supervisory and corrective powers remain.

Small-company supportMember States give qualifying EU-established SMEs priority access to national sandboxes; an AI Office sandbox gives priority to SMEs and small mid-caps. Article 11 provides simplified technical documentation for SMEs and small mid-caps, while Article 63’s simplified quality-management route is limited to qualifying SMEs without partner or linked enterprises. Substantive protection duties remain.

13 · Dates

Entry into force and application are different dates.

The Act entered into force on 1 August 2024. The timeline below reflects the enacted July 2026 amendment, not the earlier proposal.

Position from 2 August 2026

General provisions and Article 50 apply; GPAI enforcement is active. Annex III and Annex I high-risk lifecycle duties remain on the later dates enacted below.

Act enters into force

Regulation (EU) 2024/1689 enters into force, with phased application.

Definitions, literacy and original bans

Chapters I and II apply, including Article 4 and the eight original Article 5 practice families.

GPAI, governance and penalties

Chapter III Section 4, Chapter V, Chapter VII, Chapter XII and Article 78 apply, except Article 101; providers of GPAI models placed before this date retain the 2 August 2027 transition.

AI Omnibus enters into force

Regulation (EU) 2026/1744 enacts the revised dates and targeted changes; amended Articles 102–110 also apply from this date.

General date and Article 50

Most remaining provisions, Article 50 duties and Commission GPAI enforcement apply.

New bans and marking transition

The intimate-depiction and CSAM prohibitions apply. Providers of synthetic audio, image, video or text systems, including GPAI systems, placed on the market before 2 August 2026 must comply with Article 50(2)’s machine-readable marking duty by this date; the other Article 50 duties already apply from 2 August 2026.

Sandboxes and legacy GPAI

National sandboxes must be operational; pre-2 August 2025 GPAI models must comply.

Annex III high-risk duties

Chapter III Sections 1–3, except Article 6(5), apply to Article 6(2) listed-use systems, subject to Article 111’s legacy-system transition.

Annex I product high-risk duties

Chapter III Sections 1–3, except Article 6(5), apply to Article 6(1) systems, subject to Section B sector-law treatment, Article 2(13) delegated limitations and Article 111’s legacy-system transition.

Public-authority legacy systems

Providers and deployers of pre-existing high-risk systems intended for use by public authorities must comply by this date. AI components of Annex X large-scale IT systems placed on the market or put into service before 2 August 2027 must comply by 31 December 2030.

Prohibited practice

Up to €35m or 7%

Whichever ceiling is higher for an undertaking, subject to proportionality and the special SME treatment.

Listed operator and Article 50 duties

Up to €15m or 3%

Covers the specified duties in Articles 16, 22–26, 31, 33, 34 and 50, including the amended Article 25(2) and (4) value-chain cooperation duties.

Misleading information

Up to €7.5m or 1%

For incorrect, incomplete or misleading information supplied to a notified body or competent authority in reply to a request.

GPAI providers

Up to €15m or 3%

A separate Article 101 ceiling for intentional or negligent Chapter V and enforcement failures: whichever is higher for an undertaking.

AI Office operator enforcement: for Article 75(1) operators, Article 75c can apply the €15m/3% band to any applicable AI Act infringement, even one not enumerated in Article 99(4), and to failures to comply with enforcement decisions, measures or binding commitments. Misleading replies use the €7.5m/1% band. Periodic payments can reach 5% of average daily income or worldwide annual turnover in the preceding financial year per day.

Union institutions have separate ceilings: Article 100 allows the EDPS to impose up to €1.5m for Article 5 infringements and up to €750,000 for other infringements.

Ceilings are not tariffsUnder Article 99(3)–(5), SMEs receive the lower fixed or percentage ceiling. Small mid-caps receive that lower treatment only for the €15m/3% and €7.5m/1% bands. Article 101’s GPAI ceiling remains the higher amount. National regimes can also use warnings and non-monetary measures, and not every duty—Article 4 is one example—sits in a fixed €15m/3% band. Actual enforcement must remain proportionate; Member States decide how administrative fines apply to their public authorities.

14 · Operating contract

One register, then route-specific evidence.

Do not build separate spreadsheets for labels, literacy, GPAI and high-risk projects. Keep one source of truth and attach the evidence each route requires.

EU AI Act operating-register fields, records and acceptance checks
Register fieldRecordAcceptance check
System and purposeOwner, version, model, inputs, outputs, users, affected groups and intended purposeDescribes the actual workflow, not “AI-powered”
Scope and EU linkAI-system or GPAI rationale, market, establishment, output use and any exclusionEvery exclusion cites facts and a legal basis
Roles and supply chainProvider, deployer, importer, distributor, manufacturer, representative and affected peopleContracts provide required documents and technical access
Route classificationArticle 5 screen, Annex I/III test, GPAI layer, Article 50 triggers and other lawConcurrent routes remain visible
Date and ownerApplicable date, transition, accountable role and decision authorityNo bare “2026 deadline” or other relative-date language
Controls and evidenceLiteracy, data, testing, oversight, notices, conformity, review, logs and approvalsEach control has an artefact and a pass condition
Monitoring and changeIncidents, complaints, performance, model or purpose changes and review dateA trigger reopens classification before release
Inventory

Know every system

Include shadow use, vendor features, embedded product AI and retired versions still affecting people.

Decision gate

Stop before deployment

No release until scope, role, prohibition, route, date and control owner are recorded.

Change control

Reclassify material changes

New purpose, model, audience, data, autonomy, integration or brand can change risk and role.

The practical default

Classify the situation. Follow every route it triggers.