The EU AI Act in outline
What the regulation covers, who it reaches, how it is built, and the four questions every organisation has to answer for itself.
The four questions
- 01
Which systems do we deploy?
Without an inventory none of the following questions can be answered.
- 02
Are we a provider or a deployer?
Deployer as a rule. Provider if you develop, substantially modify, or offer under your own name.
- 03
Which class does each system fall into?
Prohibited, high risk, subject to transparency duties, or without particular duties.
- 04
Which duties follow, and who discharges them?
By name, not by department.
The structure in one picture
| Class | Example | Consequence |
|---|---|---|
| Prohibited | Social scoring, workplace emotion recognition | Deployment unlawful |
| High risk | Candidate selection, creditworthiness, exam marking | Full set of duties |
| Transparency duty | Chatbot, generated images and text | Disclose and label |
| Remainder | Spell checker, ticket triage | No particular duties |
Who the regulation reaches
| Role | Who that is |
|---|---|
| Provider | Develops or places on the market under their own name |
| Deployer | Uses under their own authority |
| Importer and distributor | Brings third-country systems to the internal market |
| Authorised representative | Represents a provider from a third country |
The territorial scope is broad: the regulation bites even where a provider sits outside the EU, if the output is used in the EU.
What applies to deployers
- Ensure AI literacy of the people deploying it, for all systems.
- For high risk: follow the instructions for use, human oversight by suitable people, check input data, retain logs.
- Inform those affected where a high-risk system concerns them.
- Where a transparency duty applies: disclose that a system is speaking or that content is generated.
- Report serious incidents to the provider and to market surveillance.
General-purpose models
GPAI models have their own chapter. Providers of such models must, among other things, keep technical documentation, supply information to downstream providers, maintain a copyright policy, and publish a sufficiently detailed summary of the training content.
Above a training-compute threshold, further requirements apply for systemic risk: model evaluation, risk mitigation, incident reporting and cybersecurity.
The interplay with other law
| Law | Relationship |
|---|---|
| GDPR | Applies alongside. The AI Act does not supply a legal basis. |
| Product safety law | Annex I refers to it; conformity assessment is integrated |
| Machinery Regulation | Additional requirements for safety functions |
| Copyright | Text and data mining exception, rightsholder reservation |
| Employment law | Co-determination and employee data protection unaffected |
What to do first
- Build an inventory of every system deployed, including those embedded in line-of-business applications.
- Determine and document the role per system.
- Determine the class per system, with reasoning.
- Establish AI literacy demonstrably, because that duty applies regardless of class.
- Introduce an approval process, so new systems do not bypass the inventory.
Related courses and sources
EU AI Act, the official full text
Regulation (EU) 2024/1689 in full, in every official language. The primary source for any legal question.
Our governance articles summarise and contextualise. Where the exact wording matters, this text governs.
OECD AI Principles
The international frame of reference that the European definition also draws on.
For placing national rules in an international frame.
The Commission's regulatory framework
The official overview of the AI Act with timeline, guidelines and pointers to implementing acts. The starting point for any question about deadlines.
The starting point for any deadline question, because the official timeline sits here.