AI Compass
Compass

The EU AI Act in outline

What the regulation covers, who it reaches, how it is built, and the four questions every organisation has to answer for itself.

·2 min read·By Fachbereich Governance
DETAIL
3 sections

The four questions

  1. 01

    Which systems do we deploy?

    Without an inventory none of the following questions can be answered.

  2. 02

    Are we a provider or a deployer?

    Deployer as a rule. Provider if you develop, substantially modify, or offer under your own name.

  3. 03

    Which class does each system fall into?

    Prohibited, high risk, subject to transparency duties, or without particular duties.

  4. 04

    Which duties follow, and who discharges them?

    By name, not by department.

The structure in one picture

ClassExampleConsequence
ProhibitedSocial scoring, workplace emotion recognitionDeployment unlawful
High riskCandidate selection, creditworthiness, exam markingFull set of duties
Transparency dutyChatbot, generated images and textDisclose and label
RemainderSpell checker, ticket triageNo particular duties

Who the regulation reaches

RoleWho that is
ProviderDevelops or places on the market under their own name
DeployerUses under their own authority
Importer and distributorBrings third-country systems to the internal market
Authorised representativeRepresents a provider from a third country

The territorial scope is broad: the regulation bites even where a provider sits outside the EU, if the output is used in the EU.

What applies to deployers

  • Ensure AI literacy of the people deploying it, for all systems.
  • For high risk: follow the instructions for use, human oversight by suitable people, check input data, retain logs.
  • Inform those affected where a high-risk system concerns them.
  • Where a transparency duty applies: disclose that a system is speaking or that content is generated.
  • Report serious incidents to the provider and to market surveillance.

General-purpose models

GPAI models have their own chapter. Providers of such models must, among other things, keep technical documentation, supply information to downstream providers, maintain a copyright policy, and publish a sufficiently detailed summary of the training content.

Above a training-compute threshold, further requirements apply for systemic risk: model evaluation, risk mitigation, incident reporting and cybersecurity.

The interplay with other law

LawRelationship
GDPRApplies alongside. The AI Act does not supply a legal basis.
Product safety lawAnnex I refers to it; conformity assessment is integrated
Machinery RegulationAdditional requirements for safety functions
CopyrightText and data mining exception, rightsholder reservation
Employment lawCo-determination and employee data protection unaffected

What to do first

  • Build an inventory of every system deployed, including those embedded in line-of-business applications.
  • Determine and document the role per system.
  • Determine the class per system, with reasoning.
  • Establish AI literacy demonstrably, because that duty applies regardless of class.
  • Introduce an approval process, so new systems do not bypass the inventory.

Related courses and sources

PaperFreeDE · EN

EU AI Act, the official full text

Regulation (EU) 2024/1689 in full, in every official language. The primary source for any legal question.

Our governance articles summarise and contextualise. Where the exact wording matters, this text governs.

Europäische KommissionGo to offer
ArticleFreeEN

OECD AI Principles

The international frame of reference that the European definition also draws on.

For placing national rules in an international frame.

ArticleFreeDE · EN

The Commission's regulatory framework

The official overview of the AI Act with timeline, guidelines and pointers to implementing acts. The starting point for any question about deadlines.

The starting point for any deadline question, because the official timeline sits here.

Europäische KommissionGo to offer
Was this page helpful?
The EU AI Act in outline