Does the AI Act apply to me?
The regulation's scope is extraterritorial: it covers every AI system placed on the EU market, put into service, or whose output is used in the EU — regardless of where the provider is based. Answer five questions to determine your classification and applicable obligations.
The AI Act covers any of the following cases: you are a provider placing an AI system on the EU market; you are a deployer established in the EU; you are a provider or deployer outside the EU, but the system's output is used in the EU.
Eight practices have been EU-wide prohibited since 2 February 2025 — compliance is not an option, it is a prerequisite for market access. The list covers manipulative and exploitative techniques, social scoring by public authorities, untargeted facial-image scraping, emotion recognition in workplaces and educational settings, and certain biometric categorisations.
- Subliminal, manipulative, or deceptive techniques causing significant harm
- Exploitation of vulnerabilities based on age, disability, or social situation
- Social scoring by public authorities
- Predictive policing based purely on profiling
- Untargeted scraping of facial images from the internet/CCTV
- Emotion recognition in workplaces and educational settings
- Biometric categorisation by sensitive attributes
- Real-time remote biometric identification in public spaces (narrow exceptions for law enforcement)
GPAI models are foundation models trained for a broad spectrum of tasks that can be integrated into a wide range of downstream systems — large language models are the typical example. Obligations have applied since 2 August 2025. Merely integrating a third-party model or shallow fine-tuning generally does not make you a GPAI provider — you remain a deployer or downstream provider.
A system is high-risk if it either serves as a safety component of an already regulated product (Annex I — e.g. medical devices, machinery, toys), or operates in one of the eight Annex-III domains. Profiling of natural persons is high-risk in every case.
- Biometrics (remote identification, categorisation, emotion recognition outside prohibitions)
- Critical infrastructure (transport, water, gas, electricity, critical digital infrastructure)
- Education & vocational training (access, assessment, behaviour monitoring)
- Employment (recruiting, performance, promotion, termination)
- Essential services (credit scoring, insurance pricing, social benefits, emergency response)
- Law enforcement (risk assessment, lie detection, evidence analysis)
- Migration, asylum, border control
- Justice administration & democratic processes
Even if not high-risk, transparency obligations under Art. 50 apply from 2 August 2026 for chatbots, AI-generated or AI-manipulated content (deepfakes), emotion recognition, and biometric categorisation. Obligations are usually satisfiable through appropriate notices or labels — the compliance burden is significantly lower than for high-risk systems.
- Chatbot: users must be able to recognise they are interacting with AI
- Generative AI: output must be marked as artificial in a machine-readable way (watermarking)
- Deepfakes: clear labelling as AI-generated content
- Emotion recognition / biometric categorisation: inform affected persons
AI Act likely does not apply
Without an EU nexus your system falls outside the regulation's primary scope. But note: the moment you serve EU customers, employ EU staff, or output is used in the EU, the classification changes. GDPR, product liability, anti-discrimination law, and possibly national AI rules (e.g. UK, Switzerland) remain to be checked.
Recommended next steps
- Define trigger list: which business developments require re-assessment?
- Set up internal monitoring for EU market entry and EU output use
- Voluntary alignment with AI Act anyway — competitive advantage on EU expansion
Immediate market exclusion in the EU
The system has been prohibited in the EU since 2 February 2025. Placing on the market, putting into service, and use are forbidden. There is no conformity assessment — the practice itself is unlawful. Fines reach the highest tier of the regulation.
Recommended next steps
- Immediate cessation in the EU — no postponement possible
- Legal review whether reclassification through functional change is possible
- Evaluate alternative architecture achieving the same business purpose without the prohibited practice
- Review existing contracts for liability risks, notify clients
GPAI obligations active since August 2025
As a GPAI provider you face transparency, documentation, and copyright obligations under Chapter V. Models with systemic risk (indicator: >10²⁵ FLOPs training compute) additionally face model evaluations, risk assessments, cybersecurity protection, and incident reporting. The voluntary GPAI Code of Practice (July 2025) provides a presumption of conformity.
Recommended next steps
- Prepare technical documentation under Annex XI (training data, energy use, architecture)
- Publish Public Summary of Training Content per Commission template
- Implement copyright compliance policy (EU copyright, respect opt-outs)
- Build downstream-provider information package under Annex XII
- For systemic risk: adversarial testing, incident-reporting channel to the AI Office
- Strategically evaluate signing the GPAI Code of Practice — creates a safe-harbour effect
Full conformity obligations from 2 August 2026
High-risk systems face the strictest obligation catalogue of the AI Act. You must satisfy the requirements of Art. 9 through Art. 15 (risk management, data quality, technical documentation, logging, transparency, human oversight, robustness), build a quality management system, undergo conformity assessment, carry the CE marking, and register in the EU database.
* Digital Omnibus (political agreement 7 May 2026) may postpone application dates for Annex-I systems, coupled to the availability of harmonised standards. Planning to the original date is recommended.
Recommended next steps
- Establish lifecycle risk management under Art. 9 (continuous, documented)
- Check datasets under Art. 10: representativeness, bias tests, lineage, lawful basis
- Build technical documentation under Annex IV — living document
- Implement logging architecture (Art. 12, at least 6 months retention, tamper-evident)
- Develop human oversight concept (Art. 14) — operational, not only written
- Establish QMS under Art. 17 (can build on ISO 9001 or ISO/IEC 42001)
- Choose conformity-assessment route (Art. 43) — internal for most Annex-III cases, notified body for biometrics
- Prepare post-market monitoring plan under Art. 72 — mandatory before market entry
→ Detailed requirements catalogue and 8-phase roadmap in sections 02 and 03 of this guide.
Limited risk — light obligations from August 2026
The system is not high-risk but subject to transparency requirements. Obligations are usually satisfiable in-product: clear notices, technical labelling (watermarking, metadata), machine-readable marking for synthetic content. The effort is manageable, but the risk of omission is real — fines reach €15M or 3% global turnover.
Recommended next steps
- UX audit: where and how is the AI nature communicated? Clearly, before or during interaction
- Implement watermarking strategy for generative outputs — machine-readable, state of the art
- Deepfake labelling systematically (layered approach: visual label + metadata)
- For emotion recognition / biometric categorisation: inform affected persons before processing
- Adopt Marking & Labelling Code of Practice (final mid-2026) as implementation guideline
No specific AI Act obligations
Your system falls into the largest risk category: minimal risk. Examples include spam filters, AI-assisted games, or recommendation algorithms without high-risk context. The AI Act imposes no specific obligations. Other legal regimes remain applicable — in particular GDPR, anti-discrimination law, product liability, and consumer protection.
Recommended next steps
- Define reclassification triggers: feature extensions can change status
- Implement AI literacy programme (Art. 4) — applies to all providers and deployers regardless of risk
- Consider voluntary code of conduct: builds customer trust and prepares for possible reclassification
- Re-run this decision tree on material model changes
What must be satisfied?
The following requirements apply to high-risk systems and form the core of the AI Act. Each is an independently enforceable legal obligation — and each requires solid audit evidence. The order matches Articles 9 through 15 plus complementary obligations on quality management, conformity assessment, and post-market monitoring.
Risk Management System
Continuous, iterative process across the full lifecycle. Identification, estimation, evaluation, and mitigation of all known and foreseeable risks to health, safety, and fundamental rights — including impacts on vulnerable groups and minors.
- Risk inventory with severity and likelihood
- Mitigation through design, safeguards, user information
- Testing including real-world conditions (Art. 60)
- Re-review on every material change
Data & Data Governance
Training, validation, and test data must be relevant, sufficiently representative, and as far as possible free of errors and complete with regard to the intended purpose. Bias detection and mitigation are mandatory, as is the consideration of geographic, contextual, and functional specifics.
- Data lineage and provenance documented
- Bias assessment per protected-attribute category
- Lawful basis under GDPR reviewed and recorded
- Sensitive data only where strictly necessary (Art. 10 para. 5)
Technical Documentation
Complete documentation under Annex IV before market entry, continuously updated. It covers system architecture, intended purpose, data flows, training and testing methodology, performance metrics, built-in risk controls, versioning, and limitations. It is the basis of every conformity assessment and market surveillance check.
- Annex-IV-conformant structure (living document)
- Version control with clear change history
- 10-year retention after end of market life (Art. 18)
- For SMEs: simplified form possible (Art. 11 para. 1)
Logging & Record-Keeping
The system must automatically log events across the lifecycle: inputs, outputs, operator interventions, model decisions, safety-relevant events. Logs must be tamper-evident, retained for at least 6 months, and enable traceability of relevant incidents.
- Standardised log format with timestamps
- At least 6 months retention (Art. 19)
- Tamper-evidence (hashes, append-only)
- Privacy-compliant storage (pseudonymisation)
Transparency to Deployers
Providers must give deployers, in clear, complete, and comprehensible form, all information needed for safe operation and lawful use: intended purpose, accuracy metrics, residual risks, training-data characteristics, expected lifetime, maintenance, and update requirements.
- Instructions for Use (IFU) in Annex IV format
- Performance metrics including confidence intervals
- Clearly defined misuse risks
- Instructions for human-oversight implementation
Human Oversight
The system must be designed so that natural persons can effectively oversee it during use — with the ability to intervene, override, or fully stop. Responsible persons must understand outputs, gauge limitations, and recognise automation bias.
- Designed-in stop buttons and override mechanisms
- Clear roles and competence definition for oversight personnel
- Protection against automation bias (UX, training)
- For critical applications: four-eyes principle recommended
Accuracy, Robustness, Cybersecurity
The system must maintain an appropriate level of accuracy, robustness, and cybersecurity across the lifecycle — suitable for its intended purpose. Robustness against faults, manipulation, and adversarial attacks is addressed architecturally, not only by policy.
- Measurable performance KPIs published in IFU
- Fallback modes for system failures
- Protection against data poisoning, model evasion, prompt injection
- Feedback loops for continuous improvement
Quality Management System
Providers must operate a documented QMS that organisationally anchors all obligations. It can build on existing standards (ISO 9001, ISO/IEC 42001), but must cover AI-Act-specific aspects: compliance strategy, design controls, testing procedures, conformity assessment, data management, incident reporting.
- 13 mandatory components under Art. 17 para. 1
- For SMEs: simplified form possible (Art. 63)
- Audit trail of all compliance decisions
- Integration with existing ISO 9001 / 27001 landscape recommended
Conformity Assessment + CE Marking
Before market entry: conformity assessment under Art. 43. Most Annex-III cases can be assessed internally; biometrics require a notified body. Then: EU declaration of conformity (Art. 47, 10-year retention) and CE marking (Art. 48). Only after these steps is the system lawful on the EU market.
- Choose assessment route in documented form (internal vs. notified body)
- EU Declaration of Conformity under Annex V
- Ongoing obligation: re-assessment on material changes
- Re-assessment on substantial modification
EU Database Registration
Certain high-risk systems (notably Annex III) must be registered in the public EU database before market entry. It gives authorities and the public transparency: intended purpose, provider, operational status. The entry must be updated on every material change.
- Mandatory entry before market provision
- Information per Annex VIII
- Updates on material changes
- For real-world tests additionally per Annex IX
Post-Market Monitoring
Providers must operate a documented post-market monitoring system — proactive and systematic. Goal: measure performance, accuracy, safety, and compliance across the full market lifetime. Insights feed back into risk management, technical documentation, and where needed corrective measures.
- Post-market monitoring plan before market entry
- Structured capture of performance data
- Corrective duty on risk escalation (Art. 20)
- Direct input for the continuous-compliance loop
Serious Incident Reporting
Serious incidents and malfunctions that may constitute a breach of fundamental rights must be reported to the competent national authorities. Deadlines are short — at the latest 15 days, 10 days for fatal incidents, 2 days for widespread or infrastructure-related damage.
- Incident-reporting channel and escalation process
- Deadlines: 2/10/15 days by severity
- Link to vigilance systems of other sectors (e.g. MDR for medical)
- Lessons learned fed back into risk management
How does my product become ready?
Eight phases from inventory to live operation. Duration and effort estimates are based on mid-sized B2B providers with one high-risk system. Scaling up and down is possible — with multiple systems the inventory, QMS, and conformity assessment are largely reusable.
AI Inventory & Classification
Complete capture of all AI systems in the organisation — proprietary, purchased, embedded in SaaS, in development. Classify each system by risk class with documented justification. Output: single source of truth for compliance steering. Without this base, every later phase is blind.
Gap analysis against Art. 9–15
For every high-risk system: target-actual comparison against all requirements of Chapter III, Section 2. Capture existence, maturity, and auditability of every measure. Output is a prioritised action catalogue with severity, effort, and time horizon. Common gaps: risk management not lifecycle-oriented, data lineage incomplete, logging not tamper-evident.
Governance & Quality Management System
Build or extend the QMS under Art. 17. Those already running ISO 9001 or ISO/IEC 27001 integrate the AI-Act-specific requirements — orienting on ISO/IEC 42001 (AI Management System) is recommended. Central: clear roles (AI Officer, Data Steward, oversight responsibles), documented escalation paths, version control for models and datasets.
Technical implementation of requirements
The engineering core package. Implementation of risk controls, data pipelines, logging infrastructure, human-oversight UI, robustness tests. This is where it is decided whether compliance is by design or as a bolt-on layer. The second variant is more expensive, more fragile, and harder to audit. Recommendation: treat compliance requirements like functional requirements, with acceptance criteria and CI gates.
Technical documentation under Annex IV
Creation of the full Annex-IV dossier — living document, continuously maintained. It is the heart of every audit. Contents: general system description, design specification, training methodology, data management, risks & mitigations, test procedures, performance metrics, versioning, limitations. Recommendation: structured documentation in a versionable format (e.g. markdown in the git repo next to the code), not in isolated office documents.
Conformity assessment + CE marking
Choose the assessment route under Art. 43: internal control (Annex VI) for most Annex-III cases, notified body (Annex VII) for biometrics or Annex-I-embedded systems. Then: issue the EU declaration of conformity (Annex V), apply CE marking physically or digitally, 10-year retention. On material changes — new training data, changed intended purpose, significant model updates — re-assessment is mandatory.
Registration & market entry
Entry into the EU database under Art. 49 for Annex-III systems. Only then may the system be placed on the EU market. Accompanying: update of all sales materials, contracts (especially deployer contracts with clear role boundaries) and online presence. For B2B: onboarding briefing for first deployers that operationalises the IFU in daily work.
Post-market monitoring + continuous compliance
Compliance does not end at market entry — it starts there. Post-market monitoring under Art. 72 continuously captures performance, bias drift, safety incidents, user feedback. Incidents are reported under Art. 73, corrective measures documented under Art. 20. Model updates and material changes trigger re-assessments. Recommendation: quarterly compliance review, annual full audit, trigger-based incident handling.
When is what due?
The AI Act follows a staggered application plan. Several milestones already passed — prohibitions and GPAI are active. The next and largest wave hits on 2 August 2026: high-risk Annex III, transparency obligations Art. 50, and the start of enforcement. Those not ready accept a real fine exposure.
Regulation enters into force
Regulation (EU) 2024/1689 enters into force in the EU Official Journal. The staggered application deadlines begin. From this date the EU formally has the legal basis for all subsequent obligations.
- Initial inventory of your own AI systems
- Plan compliance roadmap — with clear milestones
- Secure top-management sponsorship
Prohibitions + AI literacy applicable
Art. 5 (prohibited practices) and Art. 4 (AI literacy obligations) become applicable. The eight prohibited practices have been EU-wide forbidden since then. Every provider and deployer must additionally ensure that staff using AI systems have an adequate understanding.
- Screening all systems against Art. 5
- Roll out AI literacy programme to all staff
- Documentation: who was trained when, with what content
GPAI rules + governance applicable
Chapter V (GPAI obligations) takes effect. Providers of new GPAI models must furnish technical documentation under Annex XI, public training summary, copyright policy, and downstream information under Annex XII. Member states designate supervisory authorities, the AI Office is operational, AI Board and Scientific Panel established.
- GPAI providers: Annex-XI documentation published
- Public training summary per Commission template
- Code-of-Practice signature decided
- For systemic risk: model evaluations + incident channel
Current status — critical window
77 days to the major application date. The EU Commission reached a political agreement on the Digital Omnibus on 7 May 2026, which may postpone application dates for Annex-I systems. For Annex III the date 2 August 2026 stands unchanged. Anyone not yet in phases 5–6 of the implementation roadmap is under significant time pressure.
- Finalise technical documentation (Annex IV) — living doc, current
- Start conformity-assessment route or book notified body
- Operationally prepare post-market monitoring plan
- Test incident-reporting channel — not first after market entry
- Review deployer contracts for Art. 13/14 conformity
Main application date + enforcement start
The majority of AI Act rules take effect: high-risk obligations for Annex-III systems, transparency obligations under Art. 50 for limited-risk systems, innovation measures (at least one AI regulatory sandbox per member state), and the formal start of enforcement by national authorities and EU AI Office.
- Complete conformity documentation (Annex IV) available
- Conformity assessment completed, CE marking affixed
- EU declaration of conformity signed, 10-year retention secured
- EU database entry (Annex VIII) live
- Post-market monitoring operational
- Transparency implementation for chatbots, generative AI, deepfakes
Annex-I systems + legacy GPAI
High-risk obligations for systems embedded as safety components in regulated products (Annex I — e.g. medical devices, machinery, toys). GPAI models already on the market before 2 August 2025 must be fully compliant by this date. Note: the Digital Omnibus may couple and postpone these dates to the availability of harmonised standards.
- Integrate AI Act compliance with MDR / Machinery Directive / Toy Safety Directive
- Legacy GPAI: catch-up plan for Annex-XI documentation
- Secure notified-body capacity early (bottleneck expected)
Legacy high-risk in public bodies
High-risk systems put into service by public authorities before 2 August 2026 must be fully compliant by this date. This long transition reflects the complexity of public-sector migrations. Private providers serving authorities should align their compliance roadmap to this date.
Ongoing evolution is mandatory — not optional
Compliance is not a one-off, it is a lifecycle. After market entry several parallel cycles run: technical reviews, compliance audits, incident handling, and risk-management updates. The following cadences have proven themselves for mid-sized providers — larger organisations tend to shorter intervals, SMEs to pragmatically longer ones with clear trigger points.
Logging & Monitoring
Automated capture of performance, drift, anomalies. Alerts on threshold breach.
Bias & Drift Checks
Automated tests against protected attributes. Re-evaluation of representativeness.
Incident Review
Structured handling of all incidents — including those below reporting threshold.
Compliance Review
Status of action plans, update of technical documentation, refresh of risk matrix.
Post-Market Monitoring Report
Consolidated report for market surveillance and internal risk management.
Full Compliance Audit
Complete review against Art. 9–15 and QMS audit. Re-conformity assessment as needed.
Material Change
Model update, new intended purpose, significant data change — triggers re-assessment.
Serious-Incident Report
Deadline 2–15 days by severity. Under Art. 73 to national authority.
What is at risk?
Fines are staggered by severity of breach. Levels are above average in the European regulatory comparison — for prohibited practices they even exceed GDPR. Imposed by the national supervisory authority of the affected member state, for GPAI breaches by the EU AI Office (Art. 101).
Breach of Art. 5. Highest tier — up to €35M or 7% of global annual turnover, whichever is higher.
Breaches of obligations on high-risk systems, transparency, GPAI obligations, conformity assessment. Up to €15M or 3% global turnover.
Incorrect, incomplete, or misleading information to authorities. Up to €7.5M or 1% global turnover.
Independent sanctioning power of the EU AI Office against GPAI providers. Up to €15M or 3% global turnover.