☰
ABOUT LES Blog
Services
Legal Services GDPR Compliance Strategic Project Proposals Policy & Research Consultancy HR Policy Advisory Cybersecurity Policy Advisory AI Policy & Regulatory Advisory
Publications
Law in Brief
Cyber Law
Cyber Law
AI Act
EU AI Act
Tools
Contract Review Assistant GDPR Compliance Policy Generator CyberLEX Global Privacy Audit Engine Compliance Handbook Compliance Comparator BizLaunch Tool
Contact

EU AI Act

EU Artificial Intelligence Act (Regulation EU 2024/1689) | Directory

EU Artificial Intelligence Act (AI Act) Regulation (EU) 2024/1689 β€” Harmonised rules on Artificial Intelligence | In Force: 1 August 2024 | Applicable: 2 August 2026 (with exceptions)

Directory & Summaries

Chapter 1: General Provisions
  • Art. 1 AI ActSubject matter
    Establishes harmonised rules for placing on the market, putting into service, and using AI systems in the Union; prohibits specific AI practices; sets requirements for high-risk systems; and lays down transparency and governance rules.
  • Art. 2 AI ActScope
    Applies to providers placing AI systems or GPAI models on the EU market, deployers located in the EU, and third-country operators where system outputs are used in the EU. Excludes military, defense, and pure research activities.
  • Art. 3 AI ActDefinitions
    Defines core statutory concepts including 'AI system', 'provider', 'deployer', 'general-purpose AI model', 'systemic risk', 'biometric identification', and 'critical infrastructure'.
  • Art. 4 AI ActAI literacy
    Requires providers and deployers to take measures ensuring their staff and affected persons attain an adequate level of AI literacy regarding their rights, obligations, and risks.
Chapter 2: Prohibited AI Practices
  • Art. 5 AI ActProhibited AI Practices
    Bans subliminal manipulation, social scoring, untargeted scraping of facial images, emotion recognition in workplaces/schools, biometric categorization for sensitive traits, and real-time remote biometric identification in public spaces for law enforcement (subject to narrow exceptions).
Chapter 3: High-Risk AI Systems
Section 1: Classification
  • Art. 6 AI ActClassification rules for high-risk AI systems
    Classifies AI systems as high-risk if used as safety components of regulated products under Annex I or listed in Annex III (biometrics, infrastructure, education, employment, essential public/private services, law enforcement, migration, justice).
  • Art. 7 AI ActAmendments to Annex III
    Grants powers to the Commission to update the list of high-risk use cases in Annex III based on evolving evidence of risk to health, safety, or fundamental rights.
Section 2: Requirements for High-Risk AI Systems
  • Art. 8 AI ActCompliance with the requirements
    Mandates that high-risk AI systems comply with all requirements in Section 2, considering their intended purpose and state of the art.
  • Art. 9 AI ActRisk management system
    Requires a continuous, iterative risk management system to identify, estimate, and mitigate known and foreseeable risks throughout the AI system's entire lifecycle.
  • Art. 10 AI ActData and data governance
    Sets strict quality criteria for training, validation, and testing datasets, requiring them to be relevant, representative, free of errors, and checked for bias.
  • Art. 11 AI ActTechnical documentation
    Requires technical documentation demonstrating compliance to be drawn up before the system is placed on the market and kept updated (as detailed in Annex IV).
  • Art. 12 AI ActRecord-keeping
    High-risk AI systems must technically enable automatic logging of events ('logs') to track operation, detect risks, and facilitate post-market monitoring.
  • Art. 13 AI ActTransparency and provision of information
    Mandates that systems be designed to operate transparently, accompanied by clear instructions for use so deployers can interpret outputs and use the system appropriately.
  • Art. 14 AI ActHuman oversight
    Requires built-in operational tools allowing natural persons to oversee systems, prevent automation bias, override outputs, or interrupt operation via a 'stop' button.
  • Art. 15 AI ActAccuracy, robustness and cybersecurity
    High-risk systems must achieve adequate levels of accuracy, resilience against errors or feedback loops, and robust cybersecurity against data poisoning or adversarial attacks.
Section 3: Obligations of Operators
  • Art. 16 AI ActObligations of providers
    Outlines primary obligations for providers, including implementing QMS, keeping technical documentation, conducting conformity assessments, and taking corrective actions.
  • Art. 17 AI ActQuality management system
    Providers must maintain a documented Quality Management System (QMS) ensuring systematic compliance across strategy, design, post-market monitoring, and resource management.
  • Art. 18 AI ActDocumentation keeping
    Providers must keep documentation, certificates, and declarations of conformity for 10 years after the system is placed on the market.
  • Art. 19 AI ActAutomatically generated logs
    Providers must keep automatically generated logs under their control for at least 6 months, unless specified otherwise by law.
  • Art. 20 AI ActCorrective actions and duty of information
    Requires providers to take immediate corrective actions (withdrawal/recall) if a system is non-compliant and inform competent authorities and distributors.
  • Art. 21 AI ActCooperation with authorities
    Providers must supply national competent authorities with all necessary documentation and access to demonstrate compliance upon reasoned request.
  • Art. 22 AI ActAuthorised representatives
    Non-EU providers must appoint an EU-based authorised representative before placing high-risk AI systems on the EU market.
  • Art. 23 AI ActObligations of importers
    Importers must verify that the provider completed conformity assessments and holds documentation before placing a system on the market.
  • Art. 24 AI ActObligations of distributors
    Distributors must verify CE marking, required documentation, and provider compliance prior to making systems available on the market.
  • Art. 25 AI ActResponsibilities along the AI value chain
    Distributors, importers, or deployers become subject to provider obligations if they place a high-risk system under their brand name or substantially modify it.
  • Art. 26 AI ActObligations of deployers
    Deployers must use systems according to instructions, assign competent human overseers, monitor operation, log auto-generated data, and inform affected persons.
  • Art. 27 AI ActFundamental rights impact assessment
    Bodies governed by public law or deployers providing public services must conduct an assessment of impacts on fundamental rights prior to deploying high-risk systems.
Section 4: Notified Bodies
  • Art. 28 AI ActNotifying authorities
    Member States must designate notifying authorities responsible for assessing, designating, and monitoring conformity assessment bodies.
  • Art. 29–39Notified Body requirements & procedures
    Establishes independence, competence, impartiality, and operational obligations for notified bodies performing third-party conformity assessments.
Section 5: Conformity & Registration
  • Art. 40 AI ActHarmonised standards
    Systems conforming to European harmonised standards published in the Official Journal benefit from a presumption of conformity with core requirements.
  • Art. 41 AI ActCommon specifications
    Allows the Commission to adopt common specifications where harmonised standards do not exist or are deemed insufficient.
  • Art. 43 AI ActConformity assessment
    Mandates internal control procedures or third-party assessment by a notified body prior to placing a high-risk AI system on the market.
  • Art. 47 AI ActEU declaration of conformity
    Providers must draw up an EU declaration of conformity stating that the system meets all requirements and keep it updated.
  • Art. 48 AI ActCE marking
    CE marking must be affixed visibly, legibly, and indelibly to high-risk AI systems or their packaging before commercial distribution.
  • Art. 49 AI ActRegistration
    Providers or deployers must register themselves and their high-risk AI systems in the official EU database before placing them on the market or in service.
Chapter 4: Transparency Obligations
  • Art. 50 AI ActTransparency for specific AI systems
    Requires clear disclosure when interacting with AI (chatbots), machine-readable watermarking for AI-generated text/media, and labelling of deepfakes and public interest synthetic content.
Chapter 5: General-Purpose AI Models (GPAI)
  • Art. 51 AI ActClassification of GPAI models with systemic risk
    Classifies GPAI models as presenting systemic risk if they have high-impact capabilities (cumulative FLOPs > 10^25) or are designated by the Commission.
  • Art. 53 AI ActObligations for providers of GPAI models
    Requires technical documentation, training data summaries, compliance with EU copyright law, and cooperation with downstream integrators. Exemption applies to open-source models with non-systemic risk.
  • Art. 55 AI ActGPAI models with systemic risk
    Providers of systemic GPAI models must conduct model evaluation, adversarial testing (red-teaming), assess systemic risks, report serious incidents, and ensure cybersecurity.
  • Art. 56 AI ActCodes of practice
    Encourages the development of Codes of Practice at the Union level to guide proper application and compliance for GPAI providers prior to formal harmonised standards.
Chapter 6: Innovation Support
  • Art. 57 AI ActAI regulatory sandboxes
    Requires Member States to establish at least one operational AI regulatory sandbox to foster innovation and controlled testing before market launch.
  • Art. 60 AI ActTesting high-risk AI in real world conditions
    Establishes legal frameworks and safeguards for testing high-risk AI systems in real-world conditions outside of sandbox environments.
  • Art. 62 AI ActMeasures for SMEs and start-ups
    Provides priority access to sandboxes, lowered administrative fees, and targeted support measures for SMEs and start-ups.
Chapter 7: Governance
  • Art. 64 AI ActAI Office
    Establishes the European AI Office within the Commission to monitor and enforce rules on GPAI models and coordinate Union-level governance.
  • Art. 65 AI ActEuropean AI Board
    Establishes the European Artificial Intelligence Board, composed of representatives from Member States, to advise and assist the Commission.
  • Art. 68 AI ActScientific panel of independent experts
    Establishes a scientific panel to advise the AI Office on systemic risks, model classifications, and technical safety aspects.
  • Art. 70 AI ActNational competent authorities
    Requires each Member State to designate at least one market surveillance authority and one notifying authority responsible for national enforcement.
Chapter 8: EU Database
  • Art. 71 AI ActEU database for high-risk AI systems
    Mandates the Commission, in collaboration with Member States, to set up and maintain a publicly accessible EU database listing registered high-risk AI systems.
Chapter 9: Monitoring & Enforcement
  • Art. 72 AI ActPost-market monitoring
    Providers must maintain a post-market monitoring system to systematically collect and analyze performance data throughout the system's lifetime.
  • Art. 73 AI ActReporting of serious incidents
    Providers must report any serious incident (death, severe harm to health, critical infrastructure disruption) to market surveillance authorities within 15 days.
  • Art. 85 AI ActRight to lodge a complaint
    Grants natural or legal persons the right to submit complaints regarding non-compliance to their local market surveillance authority.
  • Art. 86 AI ActRight to explanation
    Affected persons subject to decisions based on high-risk AI outputs have the right to obtain clear, meaningful explanations regarding the AI system's role.
Chapter 12: Penalties
  • Art. 99 AI ActPenalties and administrative fines
    Sets administrative fines up to €35M or 7% of total global annual turnover for prohibited practices; up to €15M or 3% for non-compliance with requirements; and up to €7.5M or 1.5% for supplying incorrect information.
  • Art. 101 AI ActFines for GPAI model providers
    The Commission may impose fines on general-purpose AI model providers up to €15M or 3% of total global annual turnover for non-compliance.
Chapter 13: Final Provisions
  • Art. 113 AI ActEntry into force and application
    In force from 1 August 2024. Applies fully from 2 August 2026, with staged applicability: Prohibited practices (6 months), GPAI rules (12 months), and High-risk Annex I systems (36 months).

Solverwp- WordPress Theme and Plugin

LES & PARTNERS Footer