EU Artificial Intelligence Act (AI Act) Regulation (EU) 2024/1689 β Harmonised rules on Artificial Intelligence | In Force: 1 August 2024 | Applicable: 2 August 2026 (with exceptions)
Directory & Summaries
Chapter 1: General Provisions
-
Art. 1 AI ActSubject matterEstablishes harmonised rules for placing on the market, putting into service, and using AI systems in the Union; prohibits specific AI practices; sets requirements for high-risk systems; and lays down transparency and governance rules.
-
Art. 2 AI ActScopeApplies to providers placing AI systems or GPAI models on the EU market, deployers located in the EU, and third-country operators where system outputs are used in the EU. Excludes military, defense, and pure research activities.
-
Art. 3 AI ActDefinitionsDefines core statutory concepts including 'AI system', 'provider', 'deployer', 'general-purpose AI model', 'systemic risk', 'biometric identification', and 'critical infrastructure'.
-
Art. 4 AI ActAI literacyRequires providers and deployers to take measures ensuring their staff and affected persons attain an adequate level of AI literacy regarding their rights, obligations, and risks.
Chapter 2: Prohibited AI Practices
-
Art. 5 AI ActProhibited AI PracticesBans subliminal manipulation, social scoring, untargeted scraping of facial images, emotion recognition in workplaces/schools, biometric categorization for sensitive traits, and real-time remote biometric identification in public spaces for law enforcement (subject to narrow exceptions).
Chapter 3: High-Risk AI Systems
Section 1: Classification
-
Art. 6 AI ActClassification rules for high-risk AI systemsClassifies AI systems as high-risk if used as safety components of regulated products under Annex I or listed in Annex III (biometrics, infrastructure, education, employment, essential public/private services, law enforcement, migration, justice).
-
Art. 7 AI ActAmendments to Annex IIIGrants powers to the Commission to update the list of high-risk use cases in Annex III based on evolving evidence of risk to health, safety, or fundamental rights.
Section 2: Requirements for High-Risk AI Systems
-
Art. 8 AI ActCompliance with the requirementsMandates that high-risk AI systems comply with all requirements in Section 2, considering their intended purpose and state of the art.
-
Art. 9 AI ActRisk management systemRequires a continuous, iterative risk management system to identify, estimate, and mitigate known and foreseeable risks throughout the AI system's entire lifecycle.
-
Art. 10 AI ActData and data governanceSets strict quality criteria for training, validation, and testing datasets, requiring them to be relevant, representative, free of errors, and checked for bias.
-
Art. 11 AI ActTechnical documentationRequires technical documentation demonstrating compliance to be drawn up before the system is placed on the market and kept updated (as detailed in Annex IV).
-
Art. 12 AI ActRecord-keepingHigh-risk AI systems must technically enable automatic logging of events ('logs') to track operation, detect risks, and facilitate post-market monitoring.
-
Art. 13 AI ActTransparency and provision of informationMandates that systems be designed to operate transparently, accompanied by clear instructions for use so deployers can interpret outputs and use the system appropriately.
-
Art. 14 AI ActHuman oversightRequires built-in operational tools allowing natural persons to oversee systems, prevent automation bias, override outputs, or interrupt operation via a 'stop' button.
-
Art. 15 AI ActAccuracy, robustness and cybersecurityHigh-risk systems must achieve adequate levels of accuracy, resilience against errors or feedback loops, and robust cybersecurity against data poisoning or adversarial attacks.
Section 3: Obligations of Operators
-
Art. 16 AI ActObligations of providersOutlines primary obligations for providers, including implementing QMS, keeping technical documentation, conducting conformity assessments, and taking corrective actions.
-
Art. 17 AI ActQuality management systemProviders must maintain a documented Quality Management System (QMS) ensuring systematic compliance across strategy, design, post-market monitoring, and resource management.
-
Art. 18 AI ActDocumentation keepingProviders must keep documentation, certificates, and declarations of conformity for 10 years after the system is placed on the market.
-
Art. 19 AI ActAutomatically generated logsProviders must keep automatically generated logs under their control for at least 6 months, unless specified otherwise by law.
-
Art. 20 AI ActCorrective actions and duty of informationRequires providers to take immediate corrective actions (withdrawal/recall) if a system is non-compliant and inform competent authorities and distributors.
-
Art. 21 AI ActCooperation with authoritiesProviders must supply national competent authorities with all necessary documentation and access to demonstrate compliance upon reasoned request.
-
Art. 22 AI ActAuthorised representativesNon-EU providers must appoint an EU-based authorised representative before placing high-risk AI systems on the EU market.
-
Art. 23 AI ActObligations of importersImporters must verify that the provider completed conformity assessments and holds documentation before placing a system on the market.
-
Art. 24 AI ActObligations of distributorsDistributors must verify CE marking, required documentation, and provider compliance prior to making systems available on the market.
-
Art. 25 AI ActResponsibilities along the AI value chainDistributors, importers, or deployers become subject to provider obligations if they place a high-risk system under their brand name or substantially modify it.
-
Art. 26 AI ActObligations of deployersDeployers must use systems according to instructions, assign competent human overseers, monitor operation, log auto-generated data, and inform affected persons.
-
Art. 27 AI ActFundamental rights impact assessmentBodies governed by public law or deployers providing public services must conduct an assessment of impacts on fundamental rights prior to deploying high-risk systems.
Section 4: Notified Bodies
-
Art. 28 AI ActNotifying authoritiesMember States must designate notifying authorities responsible for assessing, designating, and monitoring conformity assessment bodies.
-
Art. 29β39Notified Body requirements & proceduresEstablishes independence, competence, impartiality, and operational obligations for notified bodies performing third-party conformity assessments.
Section 5: Conformity & Registration
-
Art. 40 AI ActHarmonised standardsSystems conforming to European harmonised standards published in the Official Journal benefit from a presumption of conformity with core requirements.
-
Art. 41 AI ActCommon specificationsAllows the Commission to adopt common specifications where harmonised standards do not exist or are deemed insufficient.
-
Art. 43 AI ActConformity assessmentMandates internal control procedures or third-party assessment by a notified body prior to placing a high-risk AI system on the market.
-
Art. 47 AI ActEU declaration of conformityProviders must draw up an EU declaration of conformity stating that the system meets all requirements and keep it updated.
-
Art. 48 AI ActCE markingCE marking must be affixed visibly, legibly, and indelibly to high-risk AI systems or their packaging before commercial distribution.
-
Art. 49 AI ActRegistrationProviders or deployers must register themselves and their high-risk AI systems in the official EU database before placing them on the market or in service.
Chapter 4: Transparency Obligations
-
Art. 50 AI ActTransparency for specific AI systemsRequires clear disclosure when interacting with AI (chatbots), machine-readable watermarking for AI-generated text/media, and labelling of deepfakes and public interest synthetic content.
Chapter 5: General-Purpose AI Models (GPAI)
-
Art. 51 AI ActClassification of GPAI models with systemic riskClassifies GPAI models as presenting systemic risk if they have high-impact capabilities (cumulative FLOPs > 10^25) or are designated by the Commission.
-
Art. 53 AI ActObligations for providers of GPAI modelsRequires technical documentation, training data summaries, compliance with EU copyright law, and cooperation with downstream integrators. Exemption applies to open-source models with non-systemic risk.
-
Art. 55 AI ActGPAI models with systemic riskProviders of systemic GPAI models must conduct model evaluation, adversarial testing (red-teaming), assess systemic risks, report serious incidents, and ensure cybersecurity.
-
Art. 56 AI ActCodes of practiceEncourages the development of Codes of Practice at the Union level to guide proper application and compliance for GPAI providers prior to formal harmonised standards.
Chapter 6: Innovation Support
-
Art. 57 AI ActAI regulatory sandboxesRequires Member States to establish at least one operational AI regulatory sandbox to foster innovation and controlled testing before market launch.
-
Art. 60 AI ActTesting high-risk AI in real world conditionsEstablishes legal frameworks and safeguards for testing high-risk AI systems in real-world conditions outside of sandbox environments.
-
Art. 62 AI ActMeasures for SMEs and start-upsProvides priority access to sandboxes, lowered administrative fees, and targeted support measures for SMEs and start-ups.
Chapter 7: Governance
-
Art. 64 AI ActAI OfficeEstablishes the European AI Office within the Commission to monitor and enforce rules on GPAI models and coordinate Union-level governance.
-
Art. 65 AI ActEuropean AI BoardEstablishes the European Artificial Intelligence Board, composed of representatives from Member States, to advise and assist the Commission.
-
Art. 68 AI ActScientific panel of independent expertsEstablishes a scientific panel to advise the AI Office on systemic risks, model classifications, and technical safety aspects.
-
Art. 70 AI ActNational competent authoritiesRequires each Member State to designate at least one market surveillance authority and one notifying authority responsible for national enforcement.
Chapter 8: EU Database
-
Art. 71 AI ActEU database for high-risk AI systemsMandates the Commission, in collaboration with Member States, to set up and maintain a publicly accessible EU database listing registered high-risk AI systems.
Chapter 9: Monitoring & Enforcement
-
Art. 72 AI ActPost-market monitoringProviders must maintain a post-market monitoring system to systematically collect and analyze performance data throughout the system's lifetime.
-
Art. 73 AI ActReporting of serious incidentsProviders must report any serious incident (death, severe harm to health, critical infrastructure disruption) to market surveillance authorities within 15 days.
-
Art. 85 AI ActRight to lodge a complaintGrants natural or legal persons the right to submit complaints regarding non-compliance to their local market surveillance authority.
-
Art. 86 AI ActRight to explanationAffected persons subject to decisions based on high-risk AI outputs have the right to obtain clear, meaningful explanations regarding the AI system's role.
Chapter 12: Penalties
-
Art. 99 AI ActPenalties and administrative finesSets administrative fines up to β¬35M or 7% of total global annual turnover for prohibited practices; up to β¬15M or 3% for non-compliance with requirements; and up to β¬7.5M or 1.5% for supplying incorrect information.
-
Art. 101 AI ActFines for GPAI model providersThe Commission may impose fines on general-purpose AI model providers up to β¬15M or 3% of total global annual turnover for non-compliance.
Chapter 13: Final Provisions
-
Art. 113 AI ActEntry into force and applicationIn force from 1 August 2024. Applies fully from 2 August 2026, with staged applicability: Prohibited practices (6 months), GPAI rules (12 months), and High-risk Annex I systems (36 months).
