OpenAI Shelves GPT-6.1 Astra After Safety Tests: What Went Wrong?
OpenAI shelved GPT-6.1 Astra after safety tests flagged scope, authorization and action-reporting issues. See what is confirmed and what remains...
EU AI Act Compliance: Complete Business Guide covering risk classification, obligations, deadlines, AI literacy, documentation, audits and vendor compliance.
The EU AI Act is now a major regulatory consideration for organisations that develop, provide, deploy, import, distribute or otherwise place certain AI systems and general-purpose AI models on the EU market. The Regulation uses a risk-based approach, so the obligations that apply to a business depend on factors such as its role, the AI system involved, its intended purpose and the applicable risk category.
The framework is being implemented in stages. Some provisions have applied since 2025, while the general application date was 2 August 2026. Other important requirements, particularly those relating to certain high-risk AI systems, have later application dates following the 2026 Digital Omnibus.
For businesses, compliance therefore starts with understanding which AI systems they use or provide, determining their regulatory role, classifying relevant systems and identifying the obligations that actually apply.
This guide explains the EU AI Act compliance requirements businesses need to understand in 2026, including risk classification, AI literacy, high-risk AI systems, general-purpose AI models, transparency, vendor management, audits, penalties and practical implementation.
Important: This article provides general educational information and is not legal advice. The application of the EU AI Act depends on the specific organisation, AI system, intended purpose, role and circumstances. Businesses should consult the Regulation and qualified professional advisers where necessary.
The EU AI Act is Regulation (EU) 2024/1689, which establishes harmonised rules for artificial intelligence across the European Union.
Unlike voluntary AI governance frameworks, the AI Act is an EU regulation with legally binding requirements for organisations falling within its scope. It entered into force on 1 August 2024 and has been applying progressively since 2025.
Businesses should use the current consolidated text of Regulation (EU) 2024/1689 on EUR-Lex when checking the binding legislation because the Regulation has subsequently been amended, including through the 2026 Digital Omnibus.
The AI Act follows a risk-based regulatory model. Rather than imposing identical requirements on every AI application, it establishes different rules for prohibited AI practices, high-risk AI systems, certain transparency-related systems and general-purpose AI models.
This distinction is important because an AI system that is not classified as high-risk may still be subject to other requirements.
For example, AI literacy obligations apply to providers and deployers, while specific transparency obligations apply to certain AI systems and AI-generated or manipulated content.
The AI Act should also be considered alongside other applicable legislation. An organisation using AI to process personal data may need to address both the AI Act and the GDPR, while AI incorporated into regulated products may also be subject to product-specific legislation.
Whether an organisation needs to comply depends on its role, activities and relationship with the AI system.
Article 2 establishes the scope of the Regulation, including rules covering providers, deployers, importers, distributors, product manufacturers and certain organisations established outside the EU. Businesses should therefore assess the scope provisions in Article 2 of the consolidated AI Act rather than relying on a simple EU versus non-EU distinction.
A provider is broadly an organisation that develops an AI system or general-purpose AI model, or has one developed, and places it on the market or puts it into service under its name or trademark.
Provider obligations can be extensive, particularly for high-risk AI systems.
Depending on the system, providers may need to address risk management, data governance, technical documentation, logging, transparency, human oversight, accuracy, robustness, cybersecurity, quality management, conformity assessment and post-market monitoring.
A deployer is an organisation or person using an AI system under its authority, except where the system is used in a personal non-professional activity.
An employer using an AI recruitment system, for example, may have responsibilities as a deployer even though it did not develop the technology.
This distinction matters because purchasing an AI system from a supplier does not automatically transfer all AI Act responsibilities to that supplier.
The AI Act also creates responsibilities for importers and distributors in relevant circumstances.
Product manufacturers may have additional obligations when an AI system is placed on the market or put into service together with a product under the manufacturer's name or trademark.
Non-EU providers may also need an authorised representative in the EU where the Regulation requires one.
The applicable responsibilities depend on the organisation's precise role and the circumstances surrounding the AI system.
It can.
The AI Act may apply to providers established outside the EU that place AI systems or GPAI models on the Union market. It can also apply where a provider or deployer is established in a third country but the output produced by its AI system is used in the Union.
This does not mean that every company outside the EU automatically falls within the Regulation.
International organisations should instead assess the territorial-scope conditions established by Article 2 and determine whether their activities fall within them.
The AI Act establishes different regulatory requirements according to the nature and potential risk of an AI system or practice.
|
Category |
General regulatory approach |
|
Prohibited AI practices |
Certain practices are prohibited |
|
High-risk AI systems |
Extensive requirements apply to specified systems and uses |
|
Transparency-related AI |
Specific information, disclosure or marking requirements apply |
|
GPAI models |
Specific obligations apply primarily to providers |
|
Other AI systems |
Other applicable obligations may still apply |
The categories should not be treated as a simple ranking from "regulated" to "unregulated".
A system that does not fall into the high-risk category can still trigger AI literacy or transparency requirements, for example.
Article 5 prohibits specific AI practices that the EU considers unacceptable because of their potential impact on individuals.
The prohibited practices include certain manipulative or deceptive techniques, exploitation of vulnerabilities, social scoring and particular forms of biometric identification, categorisation and predictive policing.
The exact legal wording is important because the provisions contain conditions, exceptions and specific definitions.
The 2026 amendments also introduced additional prohibited practices concerning AI systems intended to generate or manipulate certain non-consensual sexually explicit or intimate content and child sexual abuse material. These additional provisions apply from 2 December 2026.
Businesses should therefore assess potentially prohibited uses before deciding that an AI system can simply be managed through ordinary risk controls.
The AI Act establishes two principal routes for high-risk classification.
The first concerns certain AI systems that are safety components of products, or are themselves products, covered by specified EU harmonisation legislation.
The second concerns AI systems falling within specified use cases listed in Annex III.
Not every AI system used in an important business process is automatically high-risk.
The classification must be assessed against the legal criteria in Article 6 and the relevant annexes. The European Commission's guidance on the classification of high-risk AI systems can help organisations understand the Commission's interpretation, although businesses should distinguish such guidance from the binding Regulation itself.
Certain AI systems are subject to specific transparency obligations.
Article 50 is particularly important in 2026 because its transparency requirements apply from 2 August 2026.
These provisions cover circumstances including interaction with certain AI systems, machine-readable marking of certain AI-generated content, deepfakes and certain AI-generated or manipulated text concerning matters of public interest.
The European Commission's Article 50 transparency guidelines provide additional information on how these requirements should be understood.
General-purpose AI models have a separate regulatory framework under the AI Act.
The obligations primarily concern GPAI providers, with additional requirements applying to providers of models presenting systemic risk.
This means that a company using a third-party GPAI-powered application is not automatically subject to the same obligations as the organisation providing the underlying GPAI model.
An AI system that is neither prohibited nor high-risk is not necessarily outside the AI Act.
For example, providers and deployers remain subject to Article 4's AI literacy requirement, while specific AI systems may fall within Article 50 transparency obligations.
Businesses should therefore ask which obligations apply to this system and this role, rather than simply asking whether the system is high-risk.
The AI Act has a phased implementation structure, and the 2026 Digital Omnibus changed the timeline for certain high-risk AI systems.
The following timeline reflects the current regulatory position in September 2026 and should be checked against the European Commission's AI Act regulatory framework and implementation information when planning compliance activities.
|
Date |
What changes |
Who it affects |
Business action |
|
1 August 2024 |
AI Act enters into force |
Relevant operators |
Begin regulatory planning |
|
2 February 2025 |
AI literacy and most prohibited-practice provisions apply |
Providers and deployers |
Address AI literacy and prohibited-use controls |
|
2 August 2025 |
GPAI and governance provisions apply |
GPAI providers and relevant organisations |
Address applicable GPAI and governance requirements |
|
27 July 2026 |
2026 Digital Omnibus enters into force |
Relevant operators |
Reassess implementation roadmap |
|
2 August 2026 |
General application of most AI Act provisions; Article 50 applies |
Relevant operators |
Implement applicable controls |
|
2 December 2026 |
Additional Article 5 prohibitions apply; certain Article 50 transition arrangements end |
Relevant operators |
Update prohibited-use and transparency controls |
|
2 December 2027 |
Annex III high-risk provisions apply |
Relevant providers and deployers |
Complete high-risk compliance preparation |
|
2 August 2028 |
Annex I product-related high-risk provisions apply |
Relevant providers and manufacturers |
Complete applicable conformity and product requirements |
|
2 August 2027 |
Existing GPAI models placed on the market before 2 August 2025 must comply |
Relevant GPAI providers |
Complete transition |
|
2 August 2030 |
Certain existing high-risk systems used by public authorities have additional transition arrangements |
Relevant public-sector operators |
Track applicable transitional requirements |
The most important point is that 2 August 2026 is not a universal deadline for every AI Act obligation.
Some requirements applied before this date, while certain high-risk requirements have later application dates.
The revised high-risk timetable is a direct result of the 2026 Digital Omnibus, which amended the AI Act framework. Businesses can consult the official EU legislation establishing the 2026 Digital Omnibus when verifying the revised timetable.
The exact requirements depend on the organisation's role and AI systems.
Several areas deserve particular attention when establishing an EU AI Act compliance programme.
Article 4 requires providers and deployers to take measures to achieve a sufficient level of AI literacy among their staff and other persons dealing with AI systems on their behalf.
Importantly, the Regulation does not establish one mandatory training course, universal examination, fixed number of training hours or standard certificate for every organisation.
The European Commission's official AI literacy guidance and resources explain that AI literacy should take account of the knowledge, experience, education, training and context of the relevant people.
For businesses, this means AI literacy should be connected to actual responsibilities.
An employee using an AI writing tool may require different knowledge from a compliance professional reviewing AI classifications or a manager approving the use of an AI system.
Organisations should consider maintaining appropriate records of training and awareness activities as evidence of their approach.
Where the AI Act requires a risk management system, businesses need a structured process for identifying, analysing and addressing relevant risks.
This is particularly important for high-risk AI systems.
Risk management should reflect the specific AI system, intended purpose and applicable regulatory requirements rather than functioning as a generic enterprise risk document.
High-risk AI systems are subject to specific requirements concerning data and data governance.
Businesses should understand what data an AI system uses, whether the data is appropriate for its intended purpose and what processes exist to address relevant data-quality and bias risks.
Where personal data is involved, organisations may also need to address GDPR requirements.
The AI Act and GDPR are separate legal frameworks. Compliance with one does not automatically establish compliance with the other.
Certain providers, especially providers of high-risk AI systems, have extensive documentation obligations.
Records may also be important for demonstrating how an organisation classified a system, assessed relevant risks, implemented controls and monitored the system.
The documentation required depends on the role and system, so organisations should avoid creating unnecessary documentation while ensuring legally required evidence is maintained.
Human oversight is a central element of the high-risk AI framework.
It should not be reduced to the existence of a nominal human reviewer.
The relevant people need sufficient understanding and authority to identify problems, interpret system outputs and take appropriate action where required.
Transparency obligations vary according to the AI system and activity.
Article 50 introduces specific requirements covering AI interaction and certain AI-generated or manipulated content.
Businesses implementing these requirements should use the European Commission's Article 50 guidance alongside the Regulation because the application of the transparency rules depends on the relevant system and circumstance.
Compliance does not necessarily end when an AI system is deployed.
Depending on the system and the organisation's role, businesses may need processes for monitoring, incident reporting, corrective action and post-market monitoring.
This is why AI governance should include ongoing review rather than treating compliance as a one-time implementation project.
High-risk AI systems receive some of the most extensive regulatory treatment under the AI Act.
Businesses should begin with Article 6 and the relevant annexes.
The assessment should consider:
What the AI system does.
Its intended purpose.
Whether it is associated with a regulated product under the Article 6(1) route.
Whether its use falls within an Annex III category.
Whether a relevant exception or condition applies.
Whether the classification decision has been documented.
Certain Annex III systems can fall outside the high-risk classification where the conditions specified by the Regulation are satisfied.
However, organisations should document the reasoning behind such a conclusion rather than simply labelling a system "low risk".
Depending on the role and system, high-risk compliance can involve:
risk management
data and data governance
technical documentation
automatic logging
information and instructions for deployers
human oversight
accuracy
robustness
cybersecurity
quality management
conformity assessment
registration
post-market monitoring
serious incident reporting
corrective action
These requirements should not all be assigned to every business in exactly the same way.
Providers and deployers have different responsibilities under the Regulation.
A company developing an AI recruitment system may have significantly different obligations from an employer deploying that system.
Similarly, a manufacturer incorporating AI into a regulated product may face a different compliance pathway from a company using an AI-enabled productivity application.
This is why a generic high-risk checklist cannot replace a system-specific legal assessment.
General-purpose AI is particularly important for organisations developing or providing foundation models and other models capable of performing a wide range of tasks.
Article 53 establishes obligations for providers of GPAI models, including technical documentation, information for downstream AI system providers, a copyright policy and a sufficiently detailed public summary of training content.
Providers of GPAI models presenting systemic risk face additional requirements concerning model evaluation, adversarial testing, systemic-risk assessment and mitigation, serious-incident reporting and cybersecurity.
The European Commission's official GPAI provider guidance provides further information on these obligations.
GPAI obligations have applied since 2 August 2025. The Commission's enforcement powers concerning GPAI providers apply from 2 August 2026.
GPAI models placed on the market before 2 August 2025 have a transition period until 2 August 2027.
Businesses should also distinguish between the GPAI provider and downstream organisations that use the model.
The GPAI Code of Practice can provide a practical compliance tool for relevant providers, but it is voluntary. The binding requirements remain those established by the AI Act itself.
Article 50 is particularly relevant for businesses in 2026 because its transparency provisions apply from 2 August 2026.
Providers of certain interactive AI systems must ensure that people are informed that they are interacting with an AI system unless this is obvious from the circumstances.
This can be relevant to customer-service chatbots, virtual assistants and similar systems.
Businesses should assess the specific interaction and determine whether the transparency obligation applies.
The AI Act establishes requirements concerning the marking of certain AI-generated or manipulated content in machine-readable formats.
The purpose is to support transparency and make certain synthetic content more identifiable.
These requirements should not be interpreted as meaning that every piece of AI-assisted business content must receive an identical visible label.
Deployers must clearly disclose certain deepfakes.
The Regulation also contains specific rules concerning AI-generated or manipulated text published on matters of public interest, subject to the conditions and exceptions established by Article 50.
The European Commission's final Article 50 guidelines provide detailed implementation guidance for these transparency obligations.
Certain AI systems already placed on the market before 2 August 2026 benefit from a limited transition concerning Article 50(2), with the relevant compliance date extending to 2 December 2026.
A structured implementation process can help businesses translate the Regulation into operational controls. For organisations developing a broader governance programme, understanding how to comply with the EU AI Act should begin with the organisation's actual AI inventory and regulatory roles rather than with a generic policy template.
Start by identifying AI systems used, developed, purchased, integrated or provided throughout the organisation.
The inventory can record:
system name
provider
business owner
intended purpose
users
data involved
deployment environment
supplier
preliminary risk classification
applicable obligations
relevant documentation
Do not limit the inventory to projects formally labelled "AI". AI functionality can be embedded within ordinary business software.
Determine whether the organisation is acting as a provider, deployer, importer, distributor, product manufacturer or another relevant operator.
The same technology can create different obligations depending on the organisation's role.
Assess each system against:
prohibited AI practices
high-risk classification
transparency obligations
GPAI considerations
other applicable AI Act requirements
Document significant classification decisions and the reasoning behind them.
After determining the role and classification, create an obligation map.
For each system, identify:
what the organisation must do
who owns the requirement
what evidence is needed
when the obligation applies
how compliance will be reviewed
This prevents businesses from applying every AI Act requirement to every AI system.
Relevant policies can address:
acceptable AI use
prohibited AI practices
AI procurement
vendor assessment
AI literacy
data governance
human oversight
transparency
incident management
monitoring
record-keeping
Policies should reflect real business processes rather than simply reproducing regulatory language.
A mature compliance programme should be supported by evidence.
Depending on the organisation and system, this may include:
classification assessments
risk assessments
training records
supplier documentation
contracts
technical documentation
testing records
monitoring results
incident records
corrective-action records
governance approvals
AI systems, vendors, intended purposes and regulatory requirements can change.
A system that was correctly classified when introduced may later be modified or deployed for a different purpose.
Compliance should therefore include periodic review.
Small and medium-sized enterprises should not assume that the AI Act simply does not apply to them.
There is no blanket SME exemption from the Regulation.
At the same time, the 2026 Digital Omnibus introduced or expanded certain simplified arrangements for smaller organisations and small and mid-cap companies.
The European Commission's explanation of the AI Omnibus changes is useful for understanding how the revised framework affects smaller organisations.
A sensible approach to EU AI Act compliance for SMEs is to prioritise:
identifying AI systems
determining the organisation's role
screening prohibited practices
assessing high-risk classification
identifying transparency requirements
reviewing AI vendors
documenting important decisions
establishing AI literacy measures
assigning ownership
monitoring regulatory developments
The goal should be proportional governance based on the organisation's actual AI exposure.
Third-party AI tools create an important compliance issue because procurement does not automatically transfer regulatory responsibility.
A structured EU AI Act vendor compliance process should examine:
who provides the system
what AI system or model is supplied
its intended purpose
whether relevant risk classifications apply
what technical information is available
what compliance documentation the vendor can provide
what contractual commitments exist
how incidents are communicated
how material system changes are managed
what monitoring information is available
Contracts should address relevant responsibilities where appropriate.
For example, an organisation using an external AI recruitment system may remain subject to deployer responsibilities even though the vendor developed the technology.
Vendor governance should therefore be integrated into procurement, legal, privacy, information-security and AI-governance processes.
An EU AI Act compliance audit should establish whether the organisation understands its AI landscape and can demonstrate that applicable obligations have been addressed.
An internal review can examine:
AI inventory completeness
organisational roles
risk classifications
prohibited-practice screening
high-risk assessments
transparency controls
AI literacy measures
vendor assessments
documentation
human oversight
monitoring
incident management
governance ownership
regulatory deadline tracking
Evidence should correspond to the obligations that actually apply.
Depending on the organisation, this can include classification records, policies, training records, vendor documentation, risk assessments, testing results, monitoring evidence and corrective-action records.
The purpose is not to create paperwork for its own sake.
The purpose is to demonstrate how compliance decisions were reached and how relevant controls operate.
An internal assessment may uncover:
undocumented AI tools
unclear system ownership
unsupported classifications
insufficient vendor information
missing AI literacy records
inconsistent transparency controls
inadequate monitoring
outdated policies
unclear escalation routes
Identifying these weaknesses internally can make remediation more manageable.
A structured EU AI Act compliance checklist can help businesses organise implementation, but it should be treated as a starting point rather than proof of legal compliance.
Create an organisation-wide AI inventory
Identify the organisation's role for each relevant AI system
Document intended purposes
Screen systems against prohibited AI practices
Assess potential high-risk classification
Identify Article 50 transparency obligations
Identify GPAI responsibilities where relevant
Establish appropriate AI literacy measures
Review data and governance controls
Establish human oversight where required
Review AI vendors and contracts
Maintain relevant documentation
Establish monitoring and incident processes
Track application dates and transitional provisions
Review compliance periodically
Maintain evidence supporting significant decisions
Completing this checklist does not automatically establish compliance with the EU AI Act. The appropriate controls depend on the organisation's role, systems, use cases and applicable provisions.
The AI Act provides for administrative penalties that vary according to the type of infringement.
Under Article 99, infringements of prohibited AI practices can attract fines of up to €35 million or 7% of total worldwide annual turnover for the preceding financial year, whichever is higher.
Other specified breaches can attract fines of up to €15 million or 3% of worldwide annual turnover, while providing incorrect, incomplete or misleading information to certain authorities can result in fines of up to €7.5 million or 1% of worldwide annual turnover.
The Regulation contains specific provisions for SMEs and certain small and mid-cap companies concerning the applicable fine calculation.
The European Commission's official AI Act enforcement information explains the enforcement structure, while Article 99 of the consolidated AI Act on EUR-Lex contains the binding penalty provisions.
These figures are maximum statutory amounts, not automatic penalties for every violation. Authorities consider the circumstances of an infringement when determining an appropriate penalty.
For businesses, 2026 represents an important stage in the AI Act's implementation.
The general application date of 2 August 2026 has arrived, but the Regulation does not operate around a single universal compliance deadline.
Some provisions have applied since 2025, Article 50 now applies, GPAI enforcement is active, and certain high-risk provisions have later application dates.
The revised high-risk timeline should therefore form part of every organisation's compliance roadmap. The European Commission's current AI Act implementation framework should be monitored as implementation guidance continues to develop.
Businesses should avoid two common mistakes.
The first is assuming that compliance can wait until the later high-risk deadlines.
The second is assuming that every AI system must immediately satisfy the entire high-risk framework.
A more effective approach is to:
establish an AI inventory
identify organisational roles
classify systems
map applicable obligations
prioritise high-impact areas
establish governance controls
review vendors
develop AI literacy
maintain evidence
monitor regulatory developments
This approach allows the organisation to respond to the requirements that actually apply instead of creating a generic AI compliance programme disconnected from its operations.
AI Act compliance is not solely a legal or technology responsibility.
Depending on the organisation, relevant responsibilities can involve:
compliance professionals
legal teams
risk professionals
information security
procurement
HR
data protection
AI governance
managers
senior leadership
employees using AI systems
Training should help relevant personnel understand the parts of the Regulation connected to their responsibilities.
An employee using an AI writing assistant may need to understand approved use, confidentiality and transparency.
A compliance professional may need deeper knowledge of classification, obligations, evidence and governance.
A manager may need to understand how AI procurement, deployment and employee use can create organisational responsibilities.
For that reason, EU AI Act compliance training should be connected to organisational roles rather than treated as a generic presentation delivered identically to everyone.
When evaluating the best EU AI Act compliance training, businesses should look beyond course duration or the availability of a completion certificate.
Relevant evaluation criteria include:
coverage of the AI Act
explanation of risk categories
current regulatory information
role relevance
governance context
clear treatment of legal requirements
distinction between mandatory requirements and best practices
accessible delivery for relevant teams
Training does not guarantee legal compliance. It should support a wider governance programme that includes appropriate policies, assessments, controls and evidence.
The requirements surrounding EU AI Act compliance for compliance professionals are broader than simply understanding the terminology of the Regulation.
Compliance professionals may need to understand how AI Act requirements fit into existing compliance management systems, including AI inventories, classification assessments, risk processes, documentation, monitoring, audit preparation and regulatory change management.
Their role may also involve coordinating legal, procurement, privacy, security and operational stakeholders.
EU AI Act compliance for managers is particularly relevant because managers often approve or oversee operational AI use.
They may approve new AI tools, manage suppliers, oversee employees using AI or introduce AI-enabled processes.
Managers therefore need sufficient awareness to recognise when an AI use case should be escalated for compliance, privacy, security or legal review.
For organisations looking to build structured internal knowledge, EU AI Act Compliance Training from AI Governance Courses can serve as an educational resource for understanding the Regulation, its risk-based structure and relevant organisational responsibilities.
EU AI Act compliance is not a single policy, training course or checklist.
For most businesses, the process starts with understanding what AI systems exist within the organisation, determining the organisation's role, classifying relevant systems and identifying the obligations that actually apply.
From there, businesses can establish appropriate governance around prohibited practices, high-risk AI, transparency, GPAI, AI literacy, vendors, documentation, monitoring and evidence.
The 2026 regulatory position also makes timeline management important. Some requirements are already applicable, while certain high-risk obligations have later deadlines following the Digital Omnibus. Organisations should therefore build their compliance roadmaps around the specific application dates relevant to their systems rather than treating 2 August 2026 as a universal deadline.
Third-party AI requires particular attention. Procuring an AI system from a vendor does not automatically transfer every regulatory responsibility to the supplier. Vendor due diligence, contracts, documentation and ongoing monitoring should form part of the organisation's broader AI governance programme.
AI literacy is equally important. Employees, managers, compliance professionals and other relevant personnel need an appropriate understanding of the AI systems they use or oversee and the responsibilities associated with those systems.
For legal accuracy, businesses should treat the current consolidated AI Act on EUR-Lex as the primary source for the binding Regulation and use current European Commission guidance to support implementation.
For organisations developing internal capability, structured EU AI Act compliance training can complement legal review, governance processes and operational controls.
The EU AI Act is an EU regulation establishing harmonised rules for artificial intelligence using a risk-based approach. It matters because organisations can have legal obligations based on their role, AI systems, intended uses and relationship with the EU market.
It can. The Regulation can apply to certain providers outside the EU and to organisations where AI-system outputs are used in the Union. The exact territorial scope depends on the conditions established by the Regulation.
Responsibility depends on the organisation's role and the AI system. Providers, deployers, importers, distributors, product manufacturers and other relevant operators can have different obligations.
Start with Article 6 and determine whether the system falls under the product-related route or an Annex III use case. Then consider applicable exceptions and document the classification reasoning.
Key dates include 2 February 2025 for AI literacy and most prohibited practices, 2 August 2025 for GPAI obligations, 2 August 2026 for general application and Article 50, 2 December 2027 for Annex III high-risk provisions and 2 August 2028 for Annex I product-related high-risk provisions.
Providers and deployers must take appropriate measures to support AI literacy among relevant staff and other people dealing with AI systems on their behalf. The Regulation does not impose one universal course, examination or fixed number of training hours.
Potentially, yes. Using a third-party AI system does not automatically remove an organisation's responsibilities as a deployer. The applicable obligations depend on the system, use case and role.
The documentation depends on the AI system and organisational role. It can include inventories, classification assessments, risk assessments, training records, vendor information, technical documentation, monitoring records and incident evidence.
Start with an AI inventory, identify organisational roles, review classifications, map applicable obligations, assess vendors, examine documentation and determine whether relevant controls can be evidenced.
Depending on the infringement, maximum administrative fines can reach €35 million or 7% of worldwide annual turnover, or €15 million or 3% for other specified breaches. The applicable limit and actual penalty depend on the type and circumstances of the infringement.
OpenAI shelved GPT-6.1 Astra after safety tests flagged scope, authorization and action-reporting issues. See what is confirmed and what remains...
AI Law
Learn AI compliance requirements, key risks, the EU AI Act, NIST AI RMF, ISO 42001, and practical steps to build...
AI Law
Understand AI regulation in the United States in 2026, including federal rules, state AI laws, privacy, discrimination and practical compliance...