Skip to content

Regulation Tracker / European Union

The EU AI Act, article by article, as data

Regulation (EU) 2024/1689 as amended by Regulation (EU) 2026/1744 (Digital Omnibus on AI), in force 2026-07-27: 119 articles (6 inserted by the Omnibus), 180 recitals and 14 annexes — and, coded from the consolidated text, 677 distinct duties, prohibitions, rights and institutional powers, each with who it binds, the date it applies, the fine tier behind it and whether it reaches a law firm, chambers, in-house team, court or legal-AI vendor. 198 do. The text is the European Union's; the coding is SafeLegalAI's, and it describes what the Regulation says, not what anyone should do.

as of 2026-09-08 · consolidated text CELEX 02024R1689-20260727 via the Publications Office (© European Union, Decision 2011/833/EU) · coding CC BY 4.0 · obligations.json · Hugging Face · GitHub · monthly updates: EU AI Act news

119
articles, one page each
677
coded obligations
198
reach legal practice
43
dated milestones
10
authorities designated · 28 states

When each part applies

Article 113 staged the Regulation; Regulation (EU) 2026/1744 (Digital Omnibus on AI) (OJ L 2026/1744, in force 2026-07-27) moved several dates — Annex III high-risk rules to 2 December 2027, Annex I embedded high-risk to 2 August 2028, new Article 5 prohibitions from 2 December 2026, Articles 102–110 from 27 July 2026 (Commission summary). Each milestone carries its legal basis, its status on 2026-09-08 and an official source; 163 coded duties show both the 2024 date and the amended one.

DateMilestoneScopeBasisStatus
Initial delegated-power period began.Article 97(2) confers the powers for five years from 1 August 2024.Commission powers to adopt delegated acts under Articles 6, 7, 11, 43, 47, 51, 52 and 53 for five years.Art. 97(2)past source
Regulation entered into force.Official timeline lists 01 Aug 2024 as entry into force. © European Union.Entry into force of Regulation (EU) 2024/1689, twenty days after publication in the Official Journal.Art. 113past source
Member States' Article 77 authorities list due.Three months after entry into force.Public authorities or bodies supervising or enforcing Union law protecting fundamental rights were to be identified and made public.Art. 77(2)past source
Chapters I and II started to apply.The Commission timeline states general provisions/AI literacy and prohibitions apply from this date; the later Omnibus adds a new prohibition applying in December 2026.General provisions, including Article 4 AI literacy, and prohibited AI practices in Article 5 as then in force.Art. 113(a)past source
Commission published guidelines on prohibited AI practices.The page is dated 04 February 2025 and describes non-binding Commission interpretation.Article 5 prohibitions; practical guidance under Article 96.Commission announcementpast source
Commission published guidelines on the AI-system definition.Official Digital Strategy printable PDF for the Commission's AI-system-definition guidelines.Article 3(1) definition of an AI system; practical guidance under Article 96(1)(f).Commission announcementpast source
GPAI code-of-practice readiness deadline.Final GPAI Code was received by the Commission on 2025-07-10 and approved on 2025-08-01.Codes of practice for GPAI obligations in Articles 53 and 55 were to be ready at the latest by this date.Art. 56(9)past source
GPAI provider workshop held during Code drafting.The Commission's Code drafting timeline lists a GPAI provider workshop on July 2 2025.General-purpose AI Code of Practice drafting process.Commission announcementpast source
GPAI Code closing plenary held.The Commission's Code drafting timeline lists a closing plenary on July 3 2025.General-purpose AI Code of Practice drafting process.Commission announcementpast source
Commission received final GPAI Code of Practice.Official page states the Code is designed to help industry comply with GPAI rules applying from 2025-08-02.Voluntary compliance tool for GPAI transparency, copyright, safety and security obligations.Commission announcementpast source
Commission published guidelines for providers of GPAI models.Publication page dated 18 July 2025.Guidance for providers of general-purpose AI models on obligations taking effect on 2025-08-02.Commission announcementpast source
Commission and AI Board approved the GPAI Code as adequate.The Commission and AI Board confirmed the Code is an adequate voluntary tool.Adequacy assessment for voluntary demonstration of compliance with GPAI obligations.Commission announcementpast source
First annual Commission assessment cycle began.Date calculated as the first anniversary following entry into force.Annual assessment of whether Annex III and Article 5 need amendment, until the end of the delegated-power period.Art. 112(1)past source
Commission serious-incident reporting guidance deadline.Article 73(7) sets the deadline and requires regular assessment.Dedicated guidance to facilitate compliance with serious-incident reporting obligations.Art. 73(7)past source
First Member State resources report due.Repeats every two years after this date.Member States report to the Commission on financial and human resources of national competent authorities; every two years thereafter.Art. 70(6)past source
GPAI, governance, notified-body and penalty provisions started to apply.Commission timeline also states GPAI rules apply and governance must be in place.Chapter III Section 4, Chapter V, Chapter VII, Chapter XII and Article 78, except Article 101.Art. 113(b)past source
National competent authorities and single points of contact were due.Commission list says notifications are being considered and the list is updated continuously.Member States were to designate responsible market-surveillance authorities and notify the Commission of the single point of contact.Art. 70(2)past source
Commission proposed the Digital Omnibus on AI Regulation.The proposal was later adopted; the Commission's proposal page links to the 2026-07-27 entry-into-force announcement.Targeted simplification measures affecting AI Act implementation timelines and administrative obligations.Commission announcementpast source
High-risk classification guidelines deadline.Official Service Desk page states draft Guidelines were open for consultation until 2026-07-23 before formal adoption.Commission guidelines under Article 96 with practical examples of high-risk and non-high-risk AI systems.Art. 6(5)past source
Post-market monitoring-plan template implementing act deadline.Article 72(3) sets this deadline.Implementing act for a template and list of elements for high-risk AI post-market monitoring plans.Art. 72(3)past source
Commission published the final Code of Practice on AI-generated-content marking and labelling.Official page verifies final publication on 10 June 2026 and application of related transparency duties from 2026-08-02.Voluntary practical steps for Article 50 transparency obligations on generative AI and labelled content.Commission announcementpast source
AI Omnibus entered into force.Commission page links the full legislative text at https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=OJ:L_202601744.Amendments to AI Act implementation timelines, simplification, new prohibition, sandbox timing and governance/enforcement alignment.Regulation (EU) 2026/1744 (OJ L_202601744) Art. 2past source
General application date for non-deferred rules.Official timeline states the majority of rules come into force and enforcement starts for applicable rules on this date.Majority of AI Act rules, including Article 50 transparency obligations and Article 101 GPAI provider fines, except rules deferred by the AI Omnibus.Art. 113past source
Legacy high-risk AI significant-change transition date.Article 111(2) says the Regulation applies to those legacy high-risk systems only if, as from this date, they are subject to significant design changes; public-authority systems have a separate 2030 deadline.Operators of high-risk AI systems, other than Annex X large-scale IT components, placed on the market or put into service before 2026-08-02.Art. 111(2)past source
Original Annex III high-risk application date deferred.The Commission's AI Omnibus page confirms Annex III high-risk rules now apply starting 2027-12-02.High-risk AI systems listed in Annex III that would otherwise have been covered by the general application date.Regulation (EU) 2026/1744 (OJ L_202601744) Art. 1deferred source
Original national AI regulatory sandbox deadline deferred.The original Article 57(1) deadline was 2026-08-02; the official timeline now lists 2027-08-02.Member State obligation to have at least one operational AI regulatory sandbox.Regulation (EU) 2026/1744 (OJ L_202601744) Art. 1deferred source
New Omnibus prohibition and Article 50(2) transition apply.Official timeline marks this milestone with Digital Omnibus footnote.New prohibition for AI systems generating non-consensual sexual deepfakes/CSAM; transition for some providers generating synthetic content placed on the market before 2026-08-02.Regulation (EU) 2026/1744 (OJ L_202601744) Art. 1scheduled source
GPAI legacy-model compliance deadline.Article 111(3) transition for existing general-purpose AI models.Providers of GPAI models placed on the market before 2025-08-02 must comply with GPAI obligations.Art. 111(3)scheduled source
Member State AI regulatory sandboxes operational.The official timeline says Member States should have at least one AI regulatory sandbox per country operational by this date.At least one AI regulatory sandbox per Member State.Regulation (EU) 2026/1744 (OJ L_202601744) Art. 1deferred source
Original Article 6(1) Annex I high-risk application date deferred.Article 113(c) originally set 2027-08-02; AI Omnibus page confirms Annex I embedded-product rules now apply 2028-08-02.Article 6(1) high-risk AI embedded in regulated products covered by Annex I.Regulation (EU) 2026/1744 (OJ L_202601744) Art. 1deferred source
Deferred Annex III high-risk AI rules apply.Official timeline states Annex III high-risk rules apply on 02 Dec 2027 following the Digital Omnibus.Rules for high-risk AI systems in Annex III.Regulation (EU) 2026/1744 (OJ L_202601744) Art. 1deferred source
AI Office evaluation report due.One-off evaluation deadline in Article 112(5).Commission evaluation of whether the AI Office has sufficient powers, competences, enforcement role and resources.Art. 112(5)scheduled source
Deferred Annex I embedded high-risk AI rules apply.Official timeline states Annex I embedded-product high-risk rules apply on 02 Aug 2028 after the Digital Omnibus.High-risk AI embedded in regulated products/safety components covered by Annex I.Regulation (EU) 2026/1744 (OJ L_202601744) Art. 1deferred source
First targeted evaluation reports due.Repeats every four years thereafter.Commission evaluation of possible changes to Annex III area headings, Article 50 transparency measures, and supervision/governance effectiveness.Art. 112(2)scheduled source
GPAI energy-efficient standardisation review due.Repeats every four years thereafter.Progress report on standardisation deliverables for energy-efficient development of general-purpose AI models and need for further measures.Art. 112(6)scheduled source
Voluntary codes-of-conduct impact review due.Repeats every three years thereafter.Commission evaluation of voluntary codes of conduct for non-high-risk AI systems, including additional requirements and environmental sustainability.Art. 112(7)scheduled source
Delegated-power report due.Calculated as not later than nine months before the five-year delegation period ending 2029-08-01.Commission report on the delegation of powers for Articles 6, 7, 11, 43, 47, 51, 52 and 53.Art. 97(2)scheduled source
Deadline to oppose delegated-power tacit extension.Calculated as not later than three months before the five-year period ends.European Parliament or Council opposition to tacit extension of delegated powers.Art. 97(2)scheduled source
Initial delegated-power period ends or tacitly extends.Tacitly extends for identical periods unless opposed.Five-year delegation of Commission powers from 2024-08-01.Art. 97(2)scheduled source
General evaluation and review report due.Repeats every four years thereafter and reports are public.Commission report evaluating and reviewing the Regulation, including enforcement structure and possible need for a Union agency.Art. 112(3)scheduled source
Public-authority high-risk legacy-system compliance deadline.Article 111(2) transition applies in any case to systems intended to be used by public authorities.Providers and deployers of high-risk AI systems intended for public authorities and placed on the market or put into service before 2026-08-02.Art. 111(2)scheduled source
Large-scale IT-system AI components compliance deadline.Transitional deadline for Annex X large-scale IT systems.AI systems that are components of large-scale IT systems listed in Annex X and placed on the market or put into service before 2027-08-02.Art. 111(1)scheduled source
Enforcement assessment report due.Report goes to Parliament, Council and the European Economic and Social Committee.Commission assessment of enforcement, with possible amendment proposal on enforcement structure and need for a Union agency.Art. 112(13)scheduled source

Obligations by application date (Article 113 as amended): 2024-08-01 1 · 2025-02-02 45 · 2025-08-02 157 · 2026-07-27 21 · 2026-08-02 296 · 2026-12-02 6 · 2027-08-02 1 · 2027-12-02 143 · 2028-08-02 7.

By risk tier: High-risk 352 · Not tier-specific 205 · General-purpose AI 40 · GPAI with systemic risk 27 · Prohibited practice 24 · All AI systems 21 · Transparency obligations 8.

Fines, by tier

Articles 99–101 as written. "Whichever is higher" for most operators; for SMEs and start-ups Article 99(6) applies the lower of the two.

BasisConductWhoMax fixed% turnoverRule
Art. 99(3)non-compliance with the prohibition of the AI practices referred to in Article 5operators; undertakings are subject to the turnover alternative€35m7whichever is higher
Art. 99(4)non-compliance with listed operator or notified-body obligations other than Article 5providers, authorised representatives, importers, distributors, deployers and notified bodies€15m3whichever is higher
Art. 99(5)supply of incorrect, incomplete or misleading information to notified bodies or national competent authorities in reply to a requestoperators or other addressees responding to notified bodies or national competent authorities; undertakings are subject to the turnover alternative€7.5m1whichever is higher
Art. 99(6)SME/start-up cap for each fine referred to in Article 99SMEs, including start-upswhichever is lower (SMEs)
Art. 100(2)non-compliance by Union institutions, bodies, offices and agencies with the prohibition of the AI practices referred to in Article 5Union institutions, bodies, offices and agencies falling within the scope of the Regulation; EDPS imposes the fine€1.5mwhichever is higher
Art. 100(3)non-compliance by Union institutions, bodies, offices and agencies with any other AI-system requirements or obligations under the RegulationUnion institutions, bodies, offices and agencies falling within the scope of the Regulation; EDPS imposes the fine€0.75mwhichever is higher
Art. 101(1)intentional or negligent infringement by providers of general-purpose AI models of relevant provisions, information/document requests, requested measures, or access for evaluationsproviders of general-purpose AI models; Commission imposes the fine€15m3whichever is higher
Art. 99(6a)any infringement referred to in Article 99(4) or (5) committed by a small mid-cap enterprise (SMC)small mid-cap enterprises (SMCs), Art. 3(14b)whichever is lower (SMCs) — inserted by Regulation (EU) 2026/1744
Art. 75c(4)non-compliance found by the AI Office in respect of operators within its competence under Article 75(1) (certain AI systems built on general-purpose models or embedded in very large online platforms and search engines)operators subject to AI Office supervision under Art. 75(1)Article 99(3)–(7) tiers apply mutatis mutandis, imposed by the AI Office — inserted by Regulation (EU) 2026/1744

National competent authorities (Article 70)

Who enforces in each Member State — market surveillance, notifying authority and single point of contact — with designation status and source. 10 authorities designated across 28 states on the record.

What each Member State has done

147 national instruments across 32 states — the implementing act, designated authorities, Article 99 penalty regime, Article 57 sandbox (deadline 2 August 2027 after the Omnibus), guidance reaching legal practice — one page per state, dated and sourced to the gazette or authority. The Commission has not yet published its consolidated list of market surveillance authorities; where a state has no verifiable instrument its page says what was checked and when. Read the September 2026 report on national implementation →

What the Digital Omnibus changed

72 articles amended or inserted by Regulation (EU) 2026/1744 (Digital Omnibus on AI), by how much the text changed. Each article page marks the change and shows the consolidated text; the word-level diff is in the dataset (amendments).

All 119 articles

Each page carries the official text and the duties coded from it. Definitions are listed below.

Chapter II — Prohibited AI practices

Chapter III — Classification rules for high-risk AI systems

Chapter IV — Transparency obligations for providers and deployers of certain AI systems

Chapter VIII — EU database for high-risk AI systems listed in Annex III

Chapter IX — Post-market monitoring by providers and post-market monitoring plan for high-risk AI systems

Chapter XI — Exercise of the delegation

The 70 definitions (Article 3)

(1) AI system
a machine-based system that is designed to operate with varying levels of autonomy and that may exhibit adaptiveness after deployment, and that, for explicit or implicit objectives, infers, from the input it receives, how to generate outputs such as predictions, content, recommendations, or decisions that can influence physical or virtual environments
(2) risk
the combination of the probability of an occurrence of harm and the severity of that harm
(3) provider
a natural or legal person, public authority, agency or other body that develops an AI system or a general-purpose AI model or that has an AI system or a general-purpose AI model developed and places it on the market or puts the AI system into service under its own name or trademark, whether for payment or free of charge
(4) deployer
a natural or legal person, public authority, agency or other body using an AI system under its authority except where the AI system is used in the course of a personal non-professional activity
(5) authorised representative
a natural or legal person located or established in the Union who has received and accepted a written mandate from a provider of an AI system or a general-purpose AI model to, respectively, perform and carry out on its behalf the obligations and procedures established by this Regulation
(6) importer
a natural or legal person located or established in the Union that places on the market an AI system that bears the name or trademark of a natural or legal person established in a third country
(7) distributor
a natural or legal person in the supply chain, other than the provider or the importer, that makes an AI system available on the Union market
(8) operator
a provider, product manufacturer, deployer, authorised representative, importer or distributor
(9) placing on the market
the first making available of an AI system or a general-purpose AI model on the Union market
(10) making available on the market
the supply of an AI system or a general-purpose AI model for distribution or use on the Union market in the course of a commercial activity, whether in return for payment or free of charge
(11) putting into service
the supply of an AI system for first use directly to the deployer or for own use in the Union for its intended purpose
(12) intended purpose
the use for which an AI system is intended by the provider, including the specific context and conditions of use, as specified in the information supplied by the provider in the instructions for use, promotional or sales materials and statements, as well as in the technical documentation
(13) reasonably foreseeable misuse
the use of an AI system in a way that is not in accordance with its intended purpose, but which may result from reasonably foreseeable human behaviour or interaction with other systems, including other AI systems
(14) safety component
a component of a product or of an AI system which fulfils a safety function for that product or AI system, or the failure or malfunctioning of which endangers the health and safety of persons or property; for the purposes of this definition, a component fulfils a safety function where its intended purpose is to prevent or mitigate risks to health and safety of persons or property
(14a) micro, small and medium-sized enterprise’ or ‘SME
a micro, small or medium-sized enterprise as defined in Article 2 of the Annex to Recommendation 2003/361/EC
(14b) small mid-cap enterprise’ or ‘SMC
a small mid-cap enterprise as defined in point (2) of the Annex to Recommendation (EU) 2025/1099
(15) instructions for use
the information provided by the provider to inform the deployer of, in particular, an AI system’s intended purpose and proper use
(16) recall of an AI system
any measure aiming to achieve the return to the provider or taking out of service or disabling the use of an AI system made available to deployers
(17) withdrawal of an AI system
any measure aiming to prevent an AI system in the supply chain being made available on the market
(18) performance of an AI system
the ability of an AI system to achieve its intended purpose
(19) notifying authority
the national authority responsible for setting up and carrying out the necessary procedures for the assessment, designation and notification of conformity assessment bodies and for their monitoring
(20) conformity assessment
the process of demonstrating whether the requirements set out in Chapter III, Section 2 relating to a high-risk AI system have been fulfilled
(21) conformity assessment body
a body that performs third-party conformity assessment activities, including testing, certification and inspection
(22) notified body
a conformity assessment body notified in accordance with this Regulation and other relevant Union harmonisation legislation
(23) substantial modification
a change to an AI system after its placing on the market or putting into service which is not foreseen or planned in the initial conformity assessment carried out by the provider and as a result of which the compliance of the AI system with the requirements set out in Chapter III, Section 2 is affected or results in a modification to the intended purpose for which the AI system has been assessed
(24) CE marking
a marking by which a provider indicates that an AI system is in conformity with the requirements set out in Chapter III, Section 2 and other applicable Union harmonisation legislation providing for its affixing
(25) post-market monitoring system
all activities carried out by providers of AI systems to collect and review experience gained from the use of AI systems they place on the market or put into service for the purpose of identifying any need to immediately apply any necessary corrective or preventive actions
(26) market surveillance authority
the national authority carrying out the activities and taking the measures pursuant to Regulation (EU) 2019/1020
(27) harmonised standard
a harmonised standard as defined in Article 2(1), point (c), of Regulation (EU) No 1025/2012
(28) common specification
a set of technical specifications as defined in Article 2, point (4) of Regulation (EU) No 1025/2012, providing means to comply with certain requirements established under this Regulation
(29) training data
data used for training an AI system through fitting its learnable parameters
(30) validation data
data used for providing an evaluation of the trained AI system and for tuning its non-learnable parameters and its learning process in order, inter alia, to prevent underfitting or overfitting
(31) validation data set
a separate data set or part of the training data set, either as a fixed or variable split
(32) testing data
data used for providing an independent evaluation of the AI system in order to confirm the expected performance of that system before its placing on the market or putting into service
(33) input data
data provided to or directly acquired by an AI system on the basis of which the system produces an output
(34) biometric data
personal data resulting from specific technical processing relating to the physical, physiological or behavioural characteristics of a natural person, such as facial images or dactyloscopic data
(35) biometric identification
the automated recognition of physical, physiological, behavioural, or psychological human features for the purpose of establishing the identity of a natural person by comparing biometric data of that individual to biometric data of individuals stored in a database
(36) biometric verification
the automated, one-to-one verification, including authentication, of the identity of natural persons by comparing their biometric data to previously provided biometric data
(37) special categories of personal data
the categories of personal data referred to in Article 9(1) of Regulation (EU) 2016/679, Article 10 of Directive (EU) 2016/680 and Article 10(1) of Regulation (EU) 2018/1725
(38) sensitive operational data
operational data related to activities of prevention, detection, investigation or prosecution of criminal offences, the disclosure of which could jeopardise the integrity of criminal proceedings
(39) emotion recognition system
an AI system for the purpose of identifying or inferring emotions or intentions of natural persons on the basis of their biometric data
(40) biometric categorisation system
an AI system for the purpose of assigning natural persons to specific categories on the basis of their biometric data, unless it is ancillary to another commercial service and strictly necessary for objective technical reasons
(41) remote biometric identification system
an AI system for the purpose of identifying natural persons, without their active involvement, typically at a distance through the comparison of a person’s biometric data with the biometric data contained in a reference database
(42) real-time remote biometric identification system
a remote biometric identification system, whereby the capturing of biometric data, the comparison and the identification all occur without a significant delay, comprising not only instant identification, but also limited short delays in order to avoid circumvention
(43) post-remote biometric identification system
a remote biometric identification system other than a real-time remote biometric identification system
(44) publicly accessible space
any publicly or privately owned physical place accessible to an undetermined number of natural persons, regardless of whether certain conditions for access may apply, and regardless of the potential capacity restrictions
(45) law enforcement authority
(a) any public authority competent for the prevention, investigation, detection or prosecution of criminal offences or the execution of criminal penalties, including the safeguarding against and the prevention of threats to public security; or (b) any other body or entity entrusted by Member State law to exercise public authority and public powers for the purposes of the prevention, investigation, detection or prosecution of criminal offences or the execution of criminal penalties, including the safeguarding against and the prevention of threats to public security
(46) law enforcement
activities carried out by law enforcement authorities or on their behalf for the prevention, investigation, detection or prosecution of criminal offences or the execution of criminal penalties, including safeguarding against and preventing threats to public security
(47) AI Office
the Commission’s function of contributing to the implementation, monitoring and supervision of AI systems and general-purpose AI models, and AI governance, provided for in Commission Decision of 24 January 2024; references in this Regulation to the AI Office shall be construed as references to the Commission
(48) national competent authority
a notifying authority or a market surveillance authority; as regards AI systems put into service or used by Union institutions, agencies, offices and bodies, references to national competent authorities or market surveillance authorities in this Regulation shall be construed as references to the European Data Protection Supervisor
(49) serious incident
an incident or malfunctioning of an AI system that directly or indirectly leads to any of the following: (a) the death of a person, or serious harm to a person’s health; (b) a serious and irreversible disruption of the management or operation of critical infrastructure; (c) the infringement of obligations under Union law intended to protect fundamental rights; (d) serious harm to property or the environment
(50) personal data
personal data as defined in Article 4, point (1), of Regulation (EU) 2016/679
(51) non-personal data
data other than personal data as defined in Article 4, point (1), of Regulation (EU) 2016/679
(52) profiling
profiling as defined in Article 4, point (4), of Regulation (EU) 2016/679
(53) real-world testing plan
a document that describes the objectives, methodology, geographical, population and temporal scope, monitoring, organisation and conduct of testing in real-world conditions
(54) sandbox plan
a document agreed between the participating provider and the competent authority describing the objectives, conditions, timeframe, methodology and requirements for the activities carried out within the sandbox
(55) AI regulatory sandbox
a controlled framework set up by a competent authority which offers providers or prospective providers of AI systems the possibility to develop, train, validate and test, where appropriate in real-world conditions, an innovative AI system, pursuant to a sandbox plan for a limited time under regulatory supervision
(56) AI literacy
skills, knowledge and understanding that allow providers, deployers and affected persons, taking into account their respective rights and obligations in the context of this Regulation, to make an informed deployment of AI systems, as well as to gain awareness about the opportunities and risks of AI and possible harm it can cause
(57) testing in real-world conditions
the temporary testing of an AI system for its intended purpose in real-world conditions outside a laboratory or otherwise simulated environment, with a view to gathering reliable and robust data and to assessing and verifying the conformity of the AI system with the requirements of this Regulation and it does not qualify as placing the AI system on the market or putting it into service within the meaning of this Regulation, provided that all the conditions laid down in Article 57 or 60 are fulfilled
(58) subject
a natural person who participates in testing in real-world conditions
(59) informed consent
a subject’s freely given, specific, unambiguous and voluntary expression of his or her willingness to participate in a particular testing in real-world conditions, after having been informed of all aspects of the testing that are relevant to the subject’s decision to participate
(60) deep fake
AI-generated or manipulated image, audio or video content that resembles existing persons, objects, places, entities or events and would falsely appear to a person to be authentic or truthful
(61) widespread infringement
any act or omission contrary to Union law protecting the interest of individuals, which: (a) has harmed or is likely to harm the collective interests of individuals residing in at least two Member States other than the Member State in which: (i) the act or omission originated or took place; (ii) the provider concerned, or, where applicable, its authorised representative is located or established; or (iii) the deployer is established, when the infringement is committed by the deployer; (b) has caused, causes or is likely to cause harm to the collective interests of individuals and has common features, including the same unlawful practice or the same interest being infringed, and is occurring concurrently, committed by the same operator, in at least three Member States
(62) critical infrastructure
critical infrastructure as defined in Article 2, point (4), of Directive (EU) 2022/2557
(63) general-purpose AI model
an AI model, including where such an AI model is trained with a large amount of data using self-supervision at scale, that displays significant generality and is capable of competently performing a wide range of distinct tasks regardless of the way the model is placed on the market and that can be integrated into a variety of downstream systems or applications, except AI models that are used for research, development or prototyping activities before they are placed on the market
(64) high-impact capabilities
capabilities that match or exceed the capabilities recorded in the most advanced general-purpose AI models
(65) systemic risk
a risk that is specific to the high-impact capabilities of general-purpose AI models, having a significant impact on the Union market due to their reach, or due to actual or reasonably foreseeable negative effects on public health, safety, public security, fundamental rights, or the society as a whole, that can be propagated at scale across the value chain
(66) general-purpose AI system
an AI system which is based on a general-purpose AI model and which has the capability to serve a variety of purposes, both for direct use as well as for integration in other AI systems
(67) floating-point operation
any mathematical operation or assignment involving floating-point numbers, which are a subset of the real numbers typically represented on computers by an integer of fixed precision scaled by an integer exponent of a fixed base
(68) downstream provider
a provider of an AI system, including a general-purpose AI system, which integrates an AI model, regardless of whether the AI model is provided by themselves and vertically integrated or provided by another entity based on contractual relations

Cite

SafeLegalAI (published by Cognesio LLP), "EU AI Act, structured", safelegalai.com/regulation/eu-ai-act, accessed 2026-09-08. Coding CC BY 4.0; text © European Union, consolidated version of 27 July 2026 (https://eur-lex.europa.eu/eli/reg/2024/1689/2026-07-27/eng), reused under Commission Decision 2011/833/EU. Only the Official Journal text is authentic.