EU Regulation 2024/1689

EU AI Act Compliance Guide

What the Artificial Intelligence Act requires of providers and deployers of AI systems, how systems are classified by risk, what the penalties are, and when each obligation takes effect.

Aug 1, 2024
Entered into force
EUR 35M / 7%
Maximum penalty tier
Aug 2, 2027
Final application date

What is the EU AI Act?

The EU AI Act (Regulation (EU) 2024/1689) is the first comprehensive law regulating artificial intelligence. It applies a risk-based model: the higher the risk an AI system poses to health, safety, or fundamental rights, the stricter the obligations on the organizations that build and use it. The Act entered into force on August 1, 2024 and applies in phases through August 2, 2027.

The Act reaches beyond the EU. It applies to providers placing AI systems on the EU market regardless of where they are established, to deployers located in the EU, and to providers and deployers outside the EU when the system's output is used in the EU. A US company selling an AI-powered hiring tool to European customers is in scope even with no EU office.

Obligations differ by role. Providers (who develop a system or have it developed and place it on the market under their name) carry the heaviest duties. Deployers (who use an AI system in a professional capacity) have lighter but real obligations, including human oversight and, in some cases, fundamental rights impact assessments. Importers and distributors have verification duties, and a deployer that substantially modifies a high-risk system or rebrands it can inherit provider obligations.

The four risk categories

Prohibited practices (Article 5)

Banned outright since February 2, 2025. These include:

  • Subliminal or purposefully manipulative techniques that materially distort behavior and cause significant harm
  • Exploiting vulnerabilities related to age, disability, or social or economic situation
  • Social scoring by evaluating people based on social behavior or personal traits, leading to detrimental treatment
  • Predicting criminal behavior based solely on profiling or personality traits
  • Untargeted scraping of facial images to build facial recognition databases
  • Emotion inference in workplaces and schools (except for medical or safety reasons)
  • Biometric categorization to deduce race, political opinions, religious beliefs, or sexual orientation
  • Real-time remote biometric identification in public spaces for law enforcement, subject to narrow, judicially authorized exceptions

High-risk systems (Article 6 and Annexes I and III)

Two routes lead to a high-risk classification:

  • Annex I: the AI system is a safety component of a product (or is itself a product) covered by existing EU product safety law requiring third-party conformity assessment, such as medical devices, machinery, vehicles, or aviation equipment.
  • Annex III: the system is used in a listed sensitive area: biometrics, critical infrastructure, education and vocational training, employment and worker management, access to essential private and public services (including credit scoring and insurance pricing), law enforcement, migration and border control, or administration of justice and democratic processes.

An Annex III system can escape the high-risk label if it performs only a narrow procedural or preparatory task and does not materially influence decision outcomes, but the provider must document that assessment and register the system.

Transparency-risk systems (Article 50)

Systems that interact with people or generate content carry disclosure duties regardless of other classification:

  • Chatbots and conversational AI must make clear the user is interacting with a machine
  • Synthetic audio, image, video, and text content must be marked as artificially generated in a machine-readable way
  • Deepfakes must be visibly disclosed
  • People must be informed when exposed to emotion recognition or biometric categorization systems

Minimal risk

Everything else, such as spam filters, inventory optimization, or AI in video games, carries no new obligations under the Act, though voluntary codes of conduct are encouraged. Note that a general AI literacy duty (Article 4) applies to all providers and deployers regardless of risk level: staff who operate AI systems must have sufficient training to use them responsibly.

Obligations for high-risk AI systems

Providers of high-risk systems must implement, before placing the system on the market and continuously afterward:

  • Risk management system (Article 9): an iterative process across the full lifecycle to identify, evaluate, and mitigate foreseeable risks.
  • Data governance (Article 10): training, validation, and test data must be relevant, sufficiently representative, and examined for biases; data gaps and shortcomings must be documented.
  • Technical documentation (Article 11): documentation sufficient for regulators to assess conformity, kept current and retained for ten years.
  • Logging (Article 12): automatic recording of events over the system's lifetime to support traceability and post-market monitoring.
  • Transparency to deployers (Article 13): instructions for use that state the system's capabilities, limitations, and expected performance.
  • Human oversight (Article 14): the system must be designed so a person can understand its outputs, intervene, and stop it.
  • Accuracy, robustness, and cybersecurity (Article 15): appropriate performance levels declared and maintained, with resilience against errors and adversarial manipulation.
  • Quality management system, conformity assessment, CE marking, and EU database registration before market placement, plus post-market monitoring and serious incident reporting after.

Deployers of high-risk systems must use them per the provider's instructions, assign trained human oversight, monitor operation, keep logs, and in defined cases (public bodies and certain private services) complete a fundamental rights impact assessment before first use. Employers must inform workers before deploying high-risk AI in the workplace.

General-purpose AI models

Since August 2, 2025, providers of general-purpose AI (GPAI) models, including large language models, must maintain technical documentation, provide information to downstream integrators, publish a summary of training content, and implement a copyright compliance policy.

Models deemed to pose systemic risk (a presumption applies when cumulative training compute exceeds 10^25 FLOPs) face additional duties: model evaluations including adversarial testing, systemic risk assessment and mitigation, serious incident reporting, and cybersecurity protections. The EU AI Office supervises GPAI providers directly.

Penalties

Fines are tiered by violation type, using whichever of the fixed amount or turnover percentage is higher:

Violation Maximum fine
Prohibited AI practices (Article 5) EUR 35 million or 7% of global annual turnover
Most other obligations, including high-risk requirements EUR 15 million or 3% of global annual turnover
Supplying incorrect or misleading information to authorities EUR 7.5 million or 1% of global annual turnover

Enforcement is shared between national market surveillance authorities designated by each member state and the EU AI Office for general-purpose AI models. SMEs and startups benefit from the lower of the fixed amount or percentage.

Implementation timeline

August 1, 2024

The Act entered into force. No obligations applied yet; the phased schedule below started counting.

February 2, 2025

Prohibited practices banned. AI literacy duty (Article 4) applies to all providers and deployers.

August 2, 2025

GPAI model obligations apply to new models. Governance structures and penalty regimes take effect; member states designate national authorities.

August 2, 2026

Most remaining provisions apply, including the full high-risk regime for Annex III systems and the Article 50 transparency obligations.

August 2, 2027

High-risk obligations apply to Annex I systems embedded in regulated products. GPAI models placed on the market before August 2025 must be brought into compliance.

Where to start

  1. Inventory your AI systems. Include vendor tools and AI features embedded in SaaS products, not just systems you built.
  2. Classify each system against Article 5, Annex I, Annex III, and Article 50, and record the reasoning.
  3. Determine your role for each system: provider, deployer, importer, or distributor. Watch for modifications that shift deployer duties toward provider duties.
  4. Close the gaps by deadline order: confirm nothing you run touches a prohibited practice, stand up AI literacy training, then build the high-risk control set (risk management, data governance, documentation, oversight) ahead of the 2026 and 2027 dates.
  5. Coordinate with existing programs. GDPR data protection impact assessments, ISO 42001 AI management systems, and product safety conformity processes overlap heavily with AI Act requirements; reuse them rather than duplicating.

Related guides

Assess your AI Act exposure

BD Emerson helps organizations classify AI systems, build the required documentation and oversight controls, and align AI Act work with GDPR and ISO 42001 programs.