← Legislation library

European Union

EU AI Act

The EU Artificial Intelligence Act is the world's first comprehensive AI law. It classifies AI systems by risk and sets obligations for providers and deployers of high-risk systems, from risk management and data governance to human oversight, transparency, and post-market monitoring.

19 articles

Article 1

Subject matter

This Regulation lays down harmonised rules for the placing on the market, putting into service and use of artificial intelligence systems in the Union.

Article 2

Scope

This Regulation applies to providers, deployers, importers, distributors and product manufacturers of AI systems in the Union.

Article 3

Definitions

Key definitions including AI system, provider, deployer, high-risk AI system, and other terms used throughout the Regulation.

Article 4

AI literacy

Providers and deployers of AI systems shall take measures to ensure AI literacy among their staff and other persons dealing with AI systems.

Article 5

Prohibited AI practices

AI practices that are prohibited in the Union, including subliminal manipulation, social scoring, and certain biometric identification uses.

Article 6

Classification rules for high-risk AI systems

AI systems are classified as high-risk based on their intended purpose and the risks they pose to health, safety and fundamental rights.

Article 9

Risk management system

Providers of high-risk AI systems shall establish and implement a risk management system throughout the entire lifecycle.

Article 10

Data and data governance

Training, validation and testing data sets shall be subject to appropriate data governance practices.

Article 13

Transparency and provision of information to deployers

Providers shall design high-risk AI systems in a way that is sufficiently transparent for deployers to interpret the system's output and use it appropriately.

Article 14

Human oversight

High-risk AI systems shall be designed to allow effective human oversight measures to reduce risks.

Article 15

Accuracy, robustness and cybersecurity

High-risk AI systems shall be designed and developed to achieve an appropriate level of accuracy, robustness, and cybersecurity.

Article 26

Obligations of deployers of high-risk AI systems

Deployers of high-risk AI systems shall use such systems in accordance with the instructions of use.

Article 27

Fundamental rights impact assessment for high-risk AI systems

Deployers of high-risk AI systems shall carry out a fundamental rights impact assessment before putting the system into use.

Article 50

Transparency obligations for providers and deployers of certain AI systems

Providers and deployers of certain AI systems shall ensure sufficient transparency to enable users to interpret and appropriately use the output.

Article 51

Classification of general-purpose AI models as general-purpose AI models with systemic risk

A GPAI model is classified as having systemic risk if it has high-impact capabilities, presumed where the cumulative training compute exceeds 10^25 FLOPs.

Article 53

Obligations for providers of general-purpose AI models

GPAI providers must keep technical documentation, provide information to downstream providers, put in place a copyright policy, and publish a summary of training content.

Article 55

Obligations for providers of general-purpose AI models with systemic risk

Providers of GPAI models with systemic risk must perform model evaluation and adversarial testing, assess and mitigate systemic risks, track and report serious incidents, and ensure adequate cybersecurity.

Article 99

Penalties

Administrative fines for infringements of the AI Act, up to EUR 35 million or 7% of global annual turnover.

Article 113

Entry into force and application

The AI Act entered into force on 1 August 2024, with different application dates for different provisions.

Turn EU AI Act into tracked tasks

eurocompliant maps these obligations to checklists and evidence, so you can prove compliance instead of re-reading the text.

Start free trial