European Union
EU AI Act
The EU Artificial Intelligence Act is the world's first comprehensive AI law. It classifies AI systems by risk and sets obligations for providers and deployers of high-risk systems, from risk management and data governance to human oversight, transparency, and post-market monitoring.
27 articles
Subject matter
This Regulation lays down harmonised rules for the placing on the market, putting into service and use of artificial intelligence systems in the Union.
Scope
This Regulation applies to providers, deployers, importers, distributors and product manufacturers of AI systems in the Union.
Definitions
Key definitions including AI system, provider, deployer, high-risk AI system, and other terms used throughout the Regulation.
AI literacy
Providers and deployers must take measures to support the development of AI literacy of their staff and other persons dealing with AI systems. This obligation does not require guaranteeing any specific level of AI literacy of any individual.
Prohibited AI practices
AI practices that are prohibited in the Union, including subliminal manipulation, social scoring, and certain biometric identification uses. A new category (CSAM / non-consensual intimate imagery) was added by the Digital Omnibus on AI, effective 2 December 2026 — see amended_by field.
Classification rules for high-risk AI systems
AI systems are classified as high-risk based on their intended purpose and the risks they pose to health, safety and fundamental rights.
Risk management system
Providers of high-risk AI systems shall establish and implement a risk management system throughout the entire lifecycle.
Data and data governance
Training, validation and testing data sets shall be subject to appropriate data governance practices.
Technical documentation
Providers must draw up technical documentation before a high-risk AI system is placed on the market, keep it up to date, and include the minimum elements set out in Annex IV; SMEs may use a simplified form.
Record-keeping
High-risk AI systems must technically allow automatic logging of events over their lifetime, sufficient to identify risk situations and substantial modifications and to support post-market monitoring.
Transparency and provision of information to deployers
Providers shall design high-risk AI systems in a way that is sufficiently transparent for deployers to interpret the system's output and use it appropriately.
Human oversight
High-risk AI systems shall be designed to allow effective human oversight measures to reduce risks.
Accuracy, robustness and cybersecurity
High-risk AI systems shall be designed and developed to achieve an appropriate level of accuracy, robustness, and cybersecurity.
Obligations of providers of high-risk AI systems
Providers of high-risk AI systems must ensure compliance with Section 2, maintain identification details, have a quality management system, keep documentation and logs, complete conformity assessment, draw up an EU declaration of conformity, affix CE marking, register the system, take corrective action where needed, and demonstrate conformity to authorities on request.
Obligations of deployers of high-risk AI systems
Deployers of high-risk AI systems shall use such systems in accordance with the instructions of use.
Fundamental rights impact assessment for high-risk AI systems
Deployers of high-risk AI systems shall carry out a fundamental rights impact assessment before putting the system into use.
Conformity assessment
Providers choose between internal control or third-party assessment depending on the Annex III category, or follow the sectoral procedure where the system is already covered by other Union harmonisation legislation; substantial modification triggers a new assessment.
EU declaration of conformity
The provider must draw up a written EU declaration of conformity per high-risk AI system, keep it for 10 years, state that the system meets Section 2's requirements, and keep it up to date.
Registration
High-risk AI systems in Annex III (other than law-enforcement/migration systems) must be registered in the EU database before market placement or deployment; public-authority deployers must also register their use.
Transparency obligations for providers and deployers of certain AI systems
Providers and deployers of certain AI systems shall ensure sufficient transparency to enable users to interpret and appropriately use the output.
Classification of general-purpose AI models as general-purpose AI models with systemic risk
A GPAI model is classified as having systemic risk if it has high-impact capabilities, presumed where the cumulative training compute exceeds 10^25 FLOPs.
Obligations for providers of general-purpose AI models
GPAI providers must keep technical documentation, provide information to downstream providers, put in place a copyright policy, and publish a summary of training content.
Obligations for providers of general-purpose AI models with systemic risk
Providers of GPAI models with systemic risk must perform model evaluation and adversarial testing, assess and mitigate systemic risks, track and report serious incidents, and ensure adequate cybersecurity.
Post-market monitoring by providers and post-market monitoring plan for high-risk AI systems
Providers must establish a documented post-market monitoring system, proportionate to the system's risks, that actively collects and analyses performance data throughout the system's lifetime against a formal monitoring plan.
Reporting of serious incidents
Providers of high-risk AI systems must report serious incidents to market surveillance authorities, generally within 15 days of becoming aware, with shorter windows (2 days) for widespread infringements or specific serious incidents, and 10 days where death occurred.
Penalties
Administrative fines for infringements of the AI Act, up to EUR 35 million or 7% of global annual turnover.
Entry into force and application
The AI Act entered into force on 1 August 2024. As originally enacted, most high-risk obligations were due 2 August 2026 — this has since been superseded, see amendment note below.
Turn EU AI Act into tracked tasks
eurocompliant maps these obligations to checklists and evidence, so you can prove compliance instead of re-reading the text.
Start free trial