Regulation Tracker / European Union
The EU AI Act, article by article, as data
Regulation (EU) 2024/1689 as amended by Regulation (EU) 2026/1744 (Digital Omnibus on AI), in force 2026-07-27: 119 articles (6 inserted by the Omnibus), 180 recitals and 14 annexes — and, coded from the consolidated text, 677 distinct duties, prohibitions, rights and institutional powers, each with who it binds, the date it applies, the fine tier behind it and whether it reaches a law firm, chambers, in-house team, court or legal-AI vendor. 198 do. The text is the European Union's; the coding is SafeLegalAI's, and it describes what the Regulation says, not what anyone should do.
as of 2026-09-08 · consolidated text CELEX 02024R1689-20260727 via the Publications Office (© European Union, Decision 2011/833/EU) · coding CC BY 4.0 · obligations.json · Hugging Face · GitHub · monthly updates: EU AI Act news
- 119
- articles, one page each
- 677
- coded obligations
- 198
- reach legal practice
- 43
- dated milestones
- 10
- authorities designated · 28 states
When each part applies
Article 113 staged the Regulation; Regulation (EU) 2026/1744 (Digital Omnibus on AI) (OJ L 2026/1744, in force 2026-07-27) moved several dates — Annex III high-risk rules to 2 December 2027, Annex I embedded high-risk to 2 August 2028, new Article 5 prohibitions from 2 December 2026, Articles 102–110 from 27 July 2026 (Commission summary). Each milestone carries its legal basis, its status on 2026-09-08 and an official source; 163 coded duties show both the 2024 date and the amended one.
| Date | Milestone | Scope | Basis | Status |
|---|---|---|---|---|
| Initial delegated-power period began.Article 97(2) confers the powers for five years from 1 August 2024. | Commission powers to adopt delegated acts under Articles 6, 7, 11, 43, 47, 51, 52 and 53 for five years. | Art. 97(2) | past source | |
| Regulation entered into force.Official timeline lists 01 Aug 2024 as entry into force. © European Union. | Entry into force of Regulation (EU) 2024/1689, twenty days after publication in the Official Journal. | Art. 113 | past source | |
| Member States' Article 77 authorities list due.Three months after entry into force. | Public authorities or bodies supervising or enforcing Union law protecting fundamental rights were to be identified and made public. | Art. 77(2) | past source | |
| Chapters I and II started to apply.The Commission timeline states general provisions/AI literacy and prohibitions apply from this date; the later Omnibus adds a new prohibition applying in December 2026. | General provisions, including Article 4 AI literacy, and prohibited AI practices in Article 5 as then in force. | Art. 113(a) | past source | |
| Commission published guidelines on prohibited AI practices.The page is dated 04 February 2025 and describes non-binding Commission interpretation. | Article 5 prohibitions; practical guidance under Article 96. | Commission announcement | past source | |
| Commission published guidelines on the AI-system definition.Official Digital Strategy printable PDF for the Commission's AI-system-definition guidelines. | Article 3(1) definition of an AI system; practical guidance under Article 96(1)(f). | Commission announcement | past source | |
| GPAI code-of-practice readiness deadline.Final GPAI Code was received by the Commission on 2025-07-10 and approved on 2025-08-01. | Codes of practice for GPAI obligations in Articles 53 and 55 were to be ready at the latest by this date. | Art. 56(9) | past source | |
| GPAI provider workshop held during Code drafting.The Commission's Code drafting timeline lists a GPAI provider workshop on July 2 2025. | General-purpose AI Code of Practice drafting process. | Commission announcement | past source | |
| GPAI Code closing plenary held.The Commission's Code drafting timeline lists a closing plenary on July 3 2025. | General-purpose AI Code of Practice drafting process. | Commission announcement | past source | |
| Commission received final GPAI Code of Practice.Official page states the Code is designed to help industry comply with GPAI rules applying from 2025-08-02. | Voluntary compliance tool for GPAI transparency, copyright, safety and security obligations. | Commission announcement | past source | |
| Commission published guidelines for providers of GPAI models.Publication page dated 18 July 2025. | Guidance for providers of general-purpose AI models on obligations taking effect on 2025-08-02. | Commission announcement | past source | |
| Commission and AI Board approved the GPAI Code as adequate.The Commission and AI Board confirmed the Code is an adequate voluntary tool. | Adequacy assessment for voluntary demonstration of compliance with GPAI obligations. | Commission announcement | past source | |
| First annual Commission assessment cycle began.Date calculated as the first anniversary following entry into force. | Annual assessment of whether Annex III and Article 5 need amendment, until the end of the delegated-power period. | Art. 112(1) | past source | |
| Commission serious-incident reporting guidance deadline.Article 73(7) sets the deadline and requires regular assessment. | Dedicated guidance to facilitate compliance with serious-incident reporting obligations. | Art. 73(7) | past source | |
| First Member State resources report due.Repeats every two years after this date. | Member States report to the Commission on financial and human resources of national competent authorities; every two years thereafter. | Art. 70(6) | past source | |
| GPAI, governance, notified-body and penalty provisions started to apply.Commission timeline also states GPAI rules apply and governance must be in place. | Chapter III Section 4, Chapter V, Chapter VII, Chapter XII and Article 78, except Article 101. | Art. 113(b) | past source | |
| National competent authorities and single points of contact were due.Commission list says notifications are being considered and the list is updated continuously. | Member States were to designate responsible market-surveillance authorities and notify the Commission of the single point of contact. | Art. 70(2) | past source | |
| Commission proposed the Digital Omnibus on AI Regulation.The proposal was later adopted; the Commission's proposal page links to the 2026-07-27 entry-into-force announcement. | Targeted simplification measures affecting AI Act implementation timelines and administrative obligations. | Commission announcement | past source | |
| High-risk classification guidelines deadline.Official Service Desk page states draft Guidelines were open for consultation until 2026-07-23 before formal adoption. | Commission guidelines under Article 96 with practical examples of high-risk and non-high-risk AI systems. | Art. 6(5) | past source | |
| Post-market monitoring-plan template implementing act deadline.Article 72(3) sets this deadline. | Implementing act for a template and list of elements for high-risk AI post-market monitoring plans. | Art. 72(3) | past source | |
| Commission published the final Code of Practice on AI-generated-content marking and labelling.Official page verifies final publication on 10 June 2026 and application of related transparency duties from 2026-08-02. | Voluntary practical steps for Article 50 transparency obligations on generative AI and labelled content. | Commission announcement | past source | |
| AI Omnibus entered into force.Commission page links the full legislative text at https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=OJ:L_202601744. | Amendments to AI Act implementation timelines, simplification, new prohibition, sandbox timing and governance/enforcement alignment. | Regulation (EU) 2026/1744 (OJ L_202601744) Art. 2 | past source | |
| General application date for non-deferred rules.Official timeline states the majority of rules come into force and enforcement starts for applicable rules on this date. | Majority of AI Act rules, including Article 50 transparency obligations and Article 101 GPAI provider fines, except rules deferred by the AI Omnibus. | Art. 113 | past source | |
| Legacy high-risk AI significant-change transition date.Article 111(2) says the Regulation applies to those legacy high-risk systems only if, as from this date, they are subject to significant design changes; public-authority systems have a separate 2030 deadline. | Operators of high-risk AI systems, other than Annex X large-scale IT components, placed on the market or put into service before 2026-08-02. | Art. 111(2) | past source | |
| Original Annex III high-risk application date deferred.The Commission's AI Omnibus page confirms Annex III high-risk rules now apply starting 2027-12-02. | High-risk AI systems listed in Annex III that would otherwise have been covered by the general application date. | Regulation (EU) 2026/1744 (OJ L_202601744) Art. 1 | deferred source | |
| Original national AI regulatory sandbox deadline deferred.The original Article 57(1) deadline was 2026-08-02; the official timeline now lists 2027-08-02. | Member State obligation to have at least one operational AI regulatory sandbox. | Regulation (EU) 2026/1744 (OJ L_202601744) Art. 1 | deferred source | |
| New Omnibus prohibition and Article 50(2) transition apply.Official timeline marks this milestone with Digital Omnibus footnote. | New prohibition for AI systems generating non-consensual sexual deepfakes/CSAM; transition for some providers generating synthetic content placed on the market before 2026-08-02. | Regulation (EU) 2026/1744 (OJ L_202601744) Art. 1 | scheduled source | |
| GPAI legacy-model compliance deadline.Article 111(3) transition for existing general-purpose AI models. | Providers of GPAI models placed on the market before 2025-08-02 must comply with GPAI obligations. | Art. 111(3) | scheduled source | |
| Member State AI regulatory sandboxes operational.The official timeline says Member States should have at least one AI regulatory sandbox per country operational by this date. | At least one AI regulatory sandbox per Member State. | Regulation (EU) 2026/1744 (OJ L_202601744) Art. 1 | deferred source | |
| Original Article 6(1) Annex I high-risk application date deferred.Article 113(c) originally set 2027-08-02; AI Omnibus page confirms Annex I embedded-product rules now apply 2028-08-02. | Article 6(1) high-risk AI embedded in regulated products covered by Annex I. | Regulation (EU) 2026/1744 (OJ L_202601744) Art. 1 | deferred source | |
| Deferred Annex III high-risk AI rules apply.Official timeline states Annex III high-risk rules apply on 02 Dec 2027 following the Digital Omnibus. | Rules for high-risk AI systems in Annex III. | Regulation (EU) 2026/1744 (OJ L_202601744) Art. 1 | deferred source | |
| AI Office evaluation report due.One-off evaluation deadline in Article 112(5). | Commission evaluation of whether the AI Office has sufficient powers, competences, enforcement role and resources. | Art. 112(5) | scheduled source | |
| Deferred Annex I embedded high-risk AI rules apply.Official timeline states Annex I embedded-product high-risk rules apply on 02 Aug 2028 after the Digital Omnibus. | High-risk AI embedded in regulated products/safety components covered by Annex I. | Regulation (EU) 2026/1744 (OJ L_202601744) Art. 1 | deferred source | |
| First targeted evaluation reports due.Repeats every four years thereafter. | Commission evaluation of possible changes to Annex III area headings, Article 50 transparency measures, and supervision/governance effectiveness. | Art. 112(2) | scheduled source | |
| GPAI energy-efficient standardisation review due.Repeats every four years thereafter. | Progress report on standardisation deliverables for energy-efficient development of general-purpose AI models and need for further measures. | Art. 112(6) | scheduled source | |
| Voluntary codes-of-conduct impact review due.Repeats every three years thereafter. | Commission evaluation of voluntary codes of conduct for non-high-risk AI systems, including additional requirements and environmental sustainability. | Art. 112(7) | scheduled source | |
| Delegated-power report due.Calculated as not later than nine months before the five-year delegation period ending 2029-08-01. | Commission report on the delegation of powers for Articles 6, 7, 11, 43, 47, 51, 52 and 53. | Art. 97(2) | scheduled source | |
| Deadline to oppose delegated-power tacit extension.Calculated as not later than three months before the five-year period ends. | European Parliament or Council opposition to tacit extension of delegated powers. | Art. 97(2) | scheduled source | |
| Initial delegated-power period ends or tacitly extends.Tacitly extends for identical periods unless opposed. | Five-year delegation of Commission powers from 2024-08-01. | Art. 97(2) | scheduled source | |
| General evaluation and review report due.Repeats every four years thereafter and reports are public. | Commission report evaluating and reviewing the Regulation, including enforcement structure and possible need for a Union agency. | Art. 112(3) | scheduled source | |
| Public-authority high-risk legacy-system compliance deadline.Article 111(2) transition applies in any case to systems intended to be used by public authorities. | Providers and deployers of high-risk AI systems intended for public authorities and placed on the market or put into service before 2026-08-02. | Art. 111(2) | scheduled source | |
| Large-scale IT-system AI components compliance deadline.Transitional deadline for Annex X large-scale IT systems. | AI systems that are components of large-scale IT systems listed in Annex X and placed on the market or put into service before 2027-08-02. | Art. 111(1) | scheduled source | |
| Enforcement assessment report due.Report goes to Parliament, Council and the European Economic and Social Committee. | Commission assessment of enforcement, with possible amendment proposal on enforcement structure and need for a Union agency. | Art. 112(13) | scheduled source |
Obligations by application date (Article 113 as amended): 2024-08-01 1 · 2025-02-02 45 · 2025-08-02 157 · 2026-07-27 21 · 2026-08-02 296 · 2026-12-02 6 · 2027-08-02 1 · 2027-12-02 143 · 2028-08-02 7.
By risk tier: High-risk 352 · Not tier-specific 205 · General-purpose AI 40 · GPAI with systemic risk 27 · Prohibited practice 24 · All AI systems 21 · Transparency obligations 8.
What reaches legal practice
The 198 provisions coded as reaching a firm, chambers, in-house team or court that deploys AI, a court as public-authority deployer, or a legal-AI vendor as provider. Each links to its article page with the Regulation's words.
As a deployer (firms, chambers, in-house, courts)
- Art. 2(1)The Regulation applies to providers, deployers, importers, distributors, product manufacturers, authorised representatives and affected persons linked to Union-market AI systems or AI outputs used in the Union. — Provider, Deployer, Importer, Distributor, Product manufacturer, Authorised representative, Natural person
- Art. 4(1)Providers and deployers must take measures to support development of AI literacy for staff and others operating or using AI systems on their behalf, taking role, context and affected persons into account. — Provider, Deployer
- Art. 4(1) (limitation)Article 4 does not require providers or deployers to guarantee any specific level of AI literacy for any individual. — Provider, Deployer
- Art. 4a(2)Providers and deployers of other AI systems and models, and deployers of high-risk AI systems, may exceptionally process special categories of personal data only within the Article 4a(2) limits. — Provider, Deployer, GPAI model provider
- Art. 4a(2) (a)For other AI systems and models and high-risk deployers, special-category processing must be strictly necessary for bias detection and correction involving likely health, safety, fundamental-rights or discrimination impacts. — Provider, Deployer, GPAI model provider
- Art. 4a(2) (b)The exceptional processing route for other AI systems and models, and for deployers of high-risk systems, requires all Article 4a(1) conditions and safeguards to be applied. — Provider, Deployer, GPAI model provider
- Art. 5(1) (1a(b))For the new intimate-material and child-sexual-abuse-material prohibitions, use is prohibited only where the deployer uses the system for the purpose of generating or manipulating that material or performance. — Deployer
- Art. 5(1) (a)Providers, deployers and other operators are prohibited from placing on the market, putting into service or using AI systems deploying subliminal, manipulative or deceptive techniques that materially distort decisions and cause or are likely to cause significant harm. — Provider, Deployer, Any operator
- Art. 5(1) (b)Providers, deployers and other operators are prohibited from AI systems that exploit vulnerabilities linked to age, disability or social or economic situation and materially distort behaviour causing or likely causing significant harm. — Provider, Deployer, Any operator
- Art. 5(1) (ba)Providers, deployers and other operators are prohibited from AI systems that generate or manipulate realistic intimate or sexually explicit material of identifiable natural persons without freely given, specific, informed, unambiguous and explicit consent. — Provider, Deployer, Any operator
- Art. 5(1) (bb)Providers, deployers and other operators are prohibited from AI systems that generate or manipulate child sexual abuse material or performances within Directive 2011/93/EU, except where a national-law without-right defence applies. — Provider, Deployer, Any operator
- Art. 5(1) (c)Providers, deployers and other operators are prohibited from AI social-scoring systems that evaluate or classify people over time and lead to unrelated, unjustified or disproportionate detrimental treatment. — Provider, Deployer, Any operator
- Art. 5(1) (d)Providers, deployers and other operators are prohibited from AI systems making criminal-offence risk assessments based solely on profiling or personality traits, subject to the objective-facts support exception. — Provider, Deployer, Any operator
- Art. 5(1) (f)Providers, deployers and other operators are prohibited from AI systems to infer emotions in workplaces or educational institutions, except where the system is for medical or safety reasons. — Provider, Deployer, Any operator
- Art. 5(1) (g)Providers, deployers and other operators are prohibited from biometric categorisation systems that infer sensitive traits such as race, political opinions, religion, sex life or sexual orientation. — Provider, Deployer, Any operator
- Art. 5(1) (h)Law-enforcement use of real-time remote biometric identification in publicly accessible spaces is prohibited except where strictly necessary for the listed serious objectives. — Public-authority deployer
- Art. 5(2)Permitted law-enforcement use of real-time remote biometric identification must only confirm the specifically targeted individual and must account for the situation and rights-and-freedoms consequences. — Public-authority deployer
- Art. 5(3)Each law-enforcement use of real-time remote biometric identification in publicly accessible spaces must receive prior judicial or independent administrative authorisation, with urgent-use limits and deletion if refused. — Public-authority deployer, Other
- Art. 6(2)AI systems referred to in Annex III are classified as high-risk in addition to Article 6(1) product-related high-risk systems. — Provider, Deployer, Any operator
- Art. 6(2) Annex III(1)Annex III point 1 makes permitted biometric systems high-risk, including remote biometric identification, sensitive biometric categorisation and emotion recognition. — Provider, Deployer, Public-authority deployer
- Art. 6(2) Annex III(4)Annex III point 4 makes specified employment, worker-management and self-employment access AI high-risk, including recruitment, promotion, termination, task allocation and worker monitoring. — Provider, Deployer, Public-authority deployer
- Art. 6(2) Annex III(6)Annex III point 6 makes specified permitted law-enforcement AI high-risk, including victim-risk assessment, polygraphs, evidence reliability, offending risk and profiling for criminal investigations. — Provider, Deployer, Public-authority deployer
- Art. 6(2) Annex III(8)Annex III point 8 makes AI for administration of justice and democratic processes high-risk, including AI assisting judicial authorities or alternative dispute resolution with facts and law. — Provider, Deployer, Public-authority deployer
- Art. 14(3)Oversight measures must be commensurate with risk, autonomy and context of use and be built into the system where feasible or identified by the provider for deployer implementation. — Provider, Deployer
- Art. 20(2)When a high-risk AI system presents an Article 79(1) risk and the provider becomes aware, it must immediately investigate causes with the reporting deployer where applicable and inform authorities and notified bodies. — Provider, Deployer, Market surveillance authority, Notified body
- Art. 25(1) (a)A distributor, importer, deployer or other third party becomes the provider of a high-risk AI system if it puts its name or trademark on an already marketed or used high-risk AI system, subject to contractual allocation. — Distributor, Importer, Deployer, Downstream provider, Any operator
- Art. 25(1) (b)A distributor, importer, deployer or other third party becomes provider if it substantially modifies an already marketed or used high-risk AI system so it remains high-risk under Article 6. — Distributor, Importer, Deployer, Downstream provider, Any operator
- Art. 25(1) (c)A distributor, importer, deployer or other third party becomes provider if it changes the intended purpose of a non-high-risk system or general-purpose AI system so it becomes high-risk under Article 6. — Distributor, Importer, Deployer, Downstream provider, Any operator
- Art. 26(1)Deployers must take appropriate technical and organisational measures to ensure high-risk AI systems are used in accordance with the accompanying instructions for use, pursuant to paragraphs 3 and 6. — Deployer
- Art. 26(2)Deployers must assign human oversight to natural persons with the necessary competence, training, authority and support. — Deployer
- Art. 26(3)Article 26(1) and (2) do not prejudice other deployer obligations under Union or national law or the deployer’s freedom to organise resources and activities for provider-indicated human oversight. — Deployer
- Art. 26(4)Where the deployer controls input data, the deployer must ensure the input data is relevant and sufficiently representative in view of the high-risk AI system’s intended purpose. — Deployer
- Art. 26(5)Deployers must monitor operation using instructions, inform providers where relevant, notify and suspend use when Article 79 risk is suspected, and immediately escalate serious incidents. — Deployer
- Art. 26(6)Deployers must keep automatically generated logs under their control for a period appropriate to intended purpose and at least six months unless Union or national law provides otherwise. — Deployer
- Art. 26(7)Employer deployers must inform workers’ representatives and affected workers before putting into service or using a high-risk AI system at the workplace. — Deployer
- Art. 26(8)Public-authority and Union-institution deployers must comply with Article 49 registration obligations and must not use an envisaged high-risk AI system that is absent from the EU database. — Deployer, Public-authority deployer, Union institution
- Art. 26(9)Where applicable, deployers must use Article 13 information to comply with data protection impact assessment duties under GDPR or Directive (EU) 2016/680. — Deployer
- Art. 26(10)Deployers using post-remote biometric identification for targeted criminal investigations must obtain ex ante or prompt binding judicial or administrative authorisation, with each use strictly necessary for a specific offence investigation. — Deployer, Public-authority deployer
- Art. 26(11)Deployers of Annex III high-risk AI systems making or assisting decisions about natural persons must inform those persons that they are subject to use of the high-risk AI system. — Deployer
- Art. 26(12)Deployers must cooperate with relevant competent authorities in actions those authorities take concerning the high-risk AI system to implement the Regulation. — Deployer
- Art. 27(1)Before deploying specified Article 6(2) high-risk AI systems, covered public-law bodies, private public-service entities and certain credit and insurance deployers must perform a fundamental-rights impact assessment. — Deployer, Public-authority deployer
- Art. 27(1) (a-f)The FRIA must describe deployer processes, duration and frequency of use, affected persons or groups, specific harm risks, human oversight implementation and measures for materialised risks. — Deployer, Public-authority deployer
- Art. 27(2)The FRIA obligation applies to first use; deployers may rely on prior or provider assessments in similar cases but must update information when Article 27(1) elements change or become outdated. — Deployer, Public-authority deployer
- Art. 27(3)After performing a FRIA, the deployer must notify the market surveillance authority of results by submitting the completed Article 27(5) template, unless exempt under Article 46(1). — Deployer, Public-authority deployer, Market surveillance authority
- Art. 27(4)Where Article 27 obligations are already met through a GDPR or law-enforcement DPIA, the deployer may include cross-references to relevant DPIA sections or include relevant parts in the FRIA. — Deployer, Public-authority deployer
- Art. 50(4)Deployers of AI systems that generate or manipulate image, audio or video content constituting a deep fake must disclose that the content was artificially generated or manipulated, subject to law-enforcement and expressive-work limits. — Deployer
- Art. 50(5)Information required by Article 50(1) to (4) must be given clearly and distinguishably by the first interaction or exposure and must meet applicable accessibility requirements. — Provider, Deployer
- Art. 71(3)Public-authority deployers, or those acting for them, must enter Annex VIII Section C data into the EU database under Article 49. — Public-authority deployer
- Art. 73(5)Where needed for timely reporting, the provider or applicable deployer may submit an incomplete initial report followed by a complete report. — Provider, Deployer
- Art. 86(1)Affected persons subject to certain deployer decisions based on Annex III high-risk AI outputs with legal or similarly significant effects have a right to clear and meaningful explanations. — Natural person, Deployer
- Art. 86(2)The explanation right does not apply where Union or national law, in compliance with Union law, provides exceptions or restrictions to that obligation. — Deployer, Natural person
- Art. 95(2)The AI Office and Member States must facilitate codes on voluntary specific requirements for all AI systems, including ethics, environmental sustainability, AI literacy, inclusive design and vulnerable groups. — AI Office, Member State, Deployer
- Art. 99(4)Non-compliance with specified operator, notified-body and transparency provisions is subject to fines up to EUR 15,000,000 or, for undertakings, 3% of total worldwide annual turnover, whichever is higher. — Provider, Authorised representative, Importer, Distributor, Deployer, Notified body, Any operator
- Art. 99(8)Each Member State must set rules on the extent to which administrative fines may be imposed on public authorities and bodies established in that Member State. — Member State, Public-authority deployer
- Art. 111(2)Providers and deployers of high-risk AI systems intended for use by public authorities must take necessary steps to comply with AI Act requirements and obligations by 2 August 2030. — Provider, Deployer, Public-authority deployer
- Art. 113 (Art. 113(c)(i))Chapter III Sections 1 to 3, except Article 6(5), apply from 2 December 2027 for AI systems classified as high-risk under Article 6(2) and Annex III. — Provider, Deployer, Public-authority deployer
As a provider (legal-AI vendors)
- Art. 4a(1)High-risk AI providers may exceptionally process special categories of personal data only to the extent strictly necessary for bias detection and correction and subject to safeguards and the listed conditions. — Provider
- Art. 4a(1) (a)Special-category processing for high-risk bias detection and correction is conditioned on the objective not being effectively fulfilled by other data, including synthetic or anonymised data. — Provider
- Art. 4a(1) (b)Special-category data must be subject to technical limits on reuse and state-of-the-art security and privacy-preserving measures, including pseudonymisation. — Provider
- Art. 4a(1) (c)Special-category data must be secured with suitable safeguards, strict access controls and access documentation so only authorised persons with confidentiality obligations can access it. — Provider
- Art. 4a(1) (d)Special-category personal data processed under Article 4a(1) must not be transmitted, transferred or otherwise accessed by other parties. — Provider
- Art. 4a(1) (e)Special-category personal data must be deleted once the bias is corrected or the data reaches the end of its retention period, whichever occurs first. — Provider
- Art. 4a(1) (f)Records of processing activities must state why special-category processing was strictly necessary for bias detection and correction and why other data could not achieve the objective. — Provider
- Art. 5(1) (1a(a))For the new intimate-material and child-sexual-abuse-material prohibitions, placing on the market or putting into service is prohibited only where generation or manipulation is intended or reasonably foreseeable and safeguards are inadequate. — Provider, Any operator
- Art. 6(3)An Annex III AI system is not high-risk if it does not pose a significant risk of harm to health, safety or fundamental rights, including by not materially influencing decision-making outcomes. — Provider
- Art. 6(4) (assessment)A provider that treats an Annex III AI system as not high-risk must document that assessment before placing the system on the market or putting it into service. — Provider
- Art. 6(4) (authority-request)On request, the provider must give national competent authorities the documentation supporting its assessment that an Annex III AI system is not high-risk. — Provider, National competent authority
- Art. 6(4) (registration)A provider that considers an Annex III AI system not high-risk remains subject to the Article 49(2) registration obligation. — Provider
- Art. 8(1)High-risk AI systems must comply with Chapter III Section 2 requirements, taking account of intended purpose, state of the art and the Article 9 risk management system. — Provider
- Art. 9(1)Providers must establish, implement, document and maintain a risk management system for high-risk AI systems. — Provider
- Art. 9(2)The risk management system must be a continuous lifecycle process with systematic review and updating, covering risk identification, estimation, post-market risk evaluation and targeted mitigation measures. — Provider
- Art. 9(3)Article 9 risk management concerns only risks that may reasonably be mitigated or eliminated through system development, design or adequate technical information. — Provider
- Art. 9(4)Risk management measures must consider the effects and interactions of all Section 2 requirements to minimise risks while balancing implementation of those requirements. — Provider
- Art. 9(5)Risk management measures must make each residual hazard risk and the overall residual risk of high-risk AI systems acceptable. — Provider
- Art. 9(6)High-risk AI systems must be tested to identify targeted risk management measures and ensure consistent intended-purpose performance and compliance with Section 2 requirements. — Provider
- Art. 9(7)Testing procedures for high-risk AI systems may include testing in real-world conditions in accordance with Article 60. — Provider
- Art. 9(8)Testing of high-risk AI systems must occur as appropriate during development and always before market placement or service, against predefined metrics and probabilistic thresholds. — Provider
- Art. 9(9)Providers implementing risk management must consider whether the intended purpose is likely to adversely affect persons under 18 and, as appropriate, other vulnerable groups. — Provider
- Art. 9(10)Providers subject to internal risk-management requirements under other Union law may include or combine Article 9 aspects with those existing procedures. — Provider
- Art. 10(1)High-risk AI systems using training techniques must be developed using training, validation and testing datasets that meet Article 10(2), (3) and (4) quality criteria and Article 4a(1) when used. — Provider
- Art. 10(2)Training, validation and testing datasets must be subject to governance and management practices appropriate for the intended purpose of the high-risk AI system. — Provider
- Art. 10(2) (a-e)Dataset governance must address design choices, data collection and origin, data preparation, assumptions about what data represent, and availability, quantity and suitability of needed datasets. — Provider
- Art. 10(2) (f)Providers must examine datasets for biases likely to affect health and safety, negatively affect fundamental rights or lead to discrimination prohibited under Union law. — Provider
- Art. 10(2) (g)Providers must take appropriate measures to detect, prevent and mitigate possible biases identified under Article 10(2)(f). — Provider
- Art. 10(2) (h)Dataset governance must identify relevant data gaps or shortcomings that prevent compliance and how those gaps and shortcomings can be addressed. — Provider
- Art. 10(3)Training, validation and testing datasets must be relevant, sufficiently representative, as error-free and complete as possible, and have appropriate statistical properties for intended use. — Provider
- Art. 10(4)Datasets must take into account, to the extent required by intended purpose, characteristics particular to the geographical, contextual, behavioural or functional setting of use. — Provider
- Art. 10(6)For high-risk AI systems developed without model-training techniques, Article 10(2), (3) and (4) and Article 4a(1) apply only to testing datasets. — Provider
- Art. 11(1)Technical documentation for a high-risk AI system must be drawn up before market placement or putting into service and kept up to date. — Provider
- Art. 12(1)High-risk AI systems must technically allow automatic recording of events over the lifetime of the system. — Provider
- Art. 12(2)Logging capabilities must enable recording of events relevant to risk or substantial modification, post-market monitoring and deployer monitoring under Article 26(5). — Provider
- Art. 13(1)High-risk AI systems must be designed and developed so their operation is sufficiently transparent for deployers to interpret output and use it appropriately, supporting provider and deployer compliance. — Provider
- Art. 13(2)High-risk AI systems must be accompanied by instructions for use in an appropriate digital or other format with concise, complete, correct, clear, relevant, accessible and comprehensible information for deployers. — Provider
- Art. 13(3) (a)Instructions for use must state the provider’s identity and contact details and, where applicable, those of its authorised representative. — Provider
- Art. 13(3) (b)Instructions must describe intended purpose, accuracy, robustness, cybersecurity, foreseeable risk circumstances, explainability capabilities, performance for specific groups, data specifications and output interpretation information. — Provider
- Art. 13(3) (c)Instructions must identify any pre-determined changes to the high-risk AI system and its performance set by the provider at initial conformity assessment. — Provider
- Art. 13(3) (d)Instructions must describe Article 14 human oversight measures, including technical measures that help deployers interpret high-risk AI system outputs. — Provider
- Art. 13(3) (f)Where relevant, instructions must describe mechanisms in the high-risk AI system that allow deployers to properly collect, store and interpret logs under Article 12. — Provider
- Art. 14(1)High-risk AI systems must be designed and developed with appropriate human-machine interface tools so natural persons can effectively oversee them during use. — Provider
- Art. 14(2)Human oversight must aim to prevent or minimise health, safety or fundamental-rights risks from intended use or foreseeable misuse, especially where risks persist despite other Section 2 requirements. — Provider
- Art. 14(4)High-risk AI systems must be provided so assigned overseers can understand capacities and limits, monitor operation, interpret outputs, disregard or override outputs and intervene or stop the system as appropriate. — Provider
- Art. 14(4) (b-d)Oversight must enable awareness of automation bias, correct interpretation of outputs, and the ability to decide not to use, disregard, override or reverse high-risk AI outputs. — Provider
- Art. 15(1)High-risk AI systems must be designed and developed to achieve appropriate accuracy, robustness and cybersecurity and perform consistently in those respects throughout their lifecycle. — Provider
- Art. 15(3)The levels of accuracy and relevant accuracy metrics for high-risk AI systems must be declared in the accompanying instructions for use. — Provider
- Art. 15(4)High-risk AI systems must be as resilient as possible against errors, faults or inconsistencies in the system or operating environment, and technical and organisational measures must be taken. — Provider
- Art. 15(5)High-risk AI systems must be resilient against unauthorised third-party attempts to alter their use, outputs or performance by exploiting system vulnerabilities. — Provider
- Art. 16 (a)Providers must ensure their high-risk AI systems comply with the requirements in Chapter III Section 2. — Provider
- Art. 16 (b)Providers must indicate their name, trade name or mark, and contact address on the system, packaging or accompanying documentation as applicable. — Provider
- Art. 16 (c)Providers must have a quality management system that complies with Article 17. — Provider
- Art. 16 (d)Providers must keep the documentation referred to in Article 18. — Provider
- Art. 16 (e)Providers must keep automatically generated logs under their control as referred to in Article 19. — Provider
- Art. 16 (f)Providers must ensure the high-risk AI system undergoes the relevant Article 43 conformity assessment before market placement or putting into service. — Provider
- Art. 16 (g)Providers must draw up an EU declaration of conformity in accordance with Article 47. — Provider
- Art. 16 (h)Providers must affix CE marking to the high-risk AI system, packaging or documentation to indicate conformity with this Regulation. — Provider
- Art. 16 (i)Providers must comply with the Article 49(1) registration obligations for high-risk AI systems. — Provider
- Art. 16 (j)Providers must take necessary corrective actions and provide required information under Article 20. — Provider
- Art. 16 (k)Providers must demonstrate conformity with Section 2 requirements upon a reasoned request from a national competent authority. — Provider
- Art. 16 (l)Providers must ensure high-risk AI systems comply with accessibility requirements under Directives (EU) 2016/2102 and (EU) 2019/882. — Provider
- Art. 17(1)Providers must put in place a documented, systematic and orderly quality management system that ensures compliance with the Regulation. — Provider
- Art. 17(1) (a)The quality management system must include a regulatory compliance strategy, including conformity assessment and modification-management procedures. — Provider
- Art. 17(1) (b-d)The quality management system must cover design control and verification, development quality control and assurance, and examination, testing and validation procedures and frequency. — Provider
- Art. 17(1) (f-g)The quality management system must include data-management systems and procedures and the Article 9 risk management system. — Provider
- Art. 17(1) (h-i)The quality management system must include post-market monitoring and serious-incident reporting procedures. — Provider
- Art. 18(1)Providers must keep specified technical, quality-management, notified-body, certificate and EU declaration documentation available to national competent authorities for 10 years after market placement or putting into service. — Provider
- Art. 19(1)Providers must keep automatically generated high-risk AI system logs under their control for a period appropriate to intended purpose and at least six months unless other law provides otherwise. — Provider
- Art. 20(1)Providers that consider or have reason to consider their high-risk AI system non-conforming must immediately take corrective actions, including conformity, withdrawal, disabling or recall, and inform relevant operators. — Provider
- Art. 21(1)Providers must, upon reasoned request, give competent authorities all information and documentation necessary to demonstrate Section 2 conformity in an easily understood official Union language indicated by the Member State. — Provider, National competent authority
- Art. 21(2)Providers must, upon reasoned request, give competent authorities access to automatically generated logs to the extent those logs are under provider control. — Provider, National competent authority
- Art. 22(1)Before making high-risk AI systems available on the Union market, third-country providers must appoint by written mandate an authorised representative established in the Union. — Provider, Authorised representative
- Art. 25(2)Where Article 25(1) circumstances occur, the provider that initially placed the AI system on the market or put it into service is no longer considered provider of that specific system. — Provider, Downstream provider
- Art. 25(4)The high-risk AI provider and third-party suppliers of integrated AI systems, AI models, tools, services, components or processes must specify necessary information, capabilities, technical access and assistance by written agreement. — Provider, Downstream provider, Any operator, GPAI model provider
- Art. 43(2)For Annex III points 2 to 8 high-risk AI systems, providers must use the Annex VI internal-control conformity assessment procedure without notified-body involvement. — Provider
- Art. 43(4)A high-risk AI system that has already undergone conformity assessment must undergo a new assessment after a substantial modification, whether redistributed or continued in use by the current deployer. — Provider
- Art. 50(1)Providers must design and develop AI systems intended to interact directly with natural persons so those persons are informed they are interacting with AI, unless obvious or covered by the specified law-enforcement exception. — Provider
- Art. 50(2)Providers of AI systems, including GPAI systems, that generate synthetic audio, image, video or text content must mark outputs in machine-readable and detectable form, subject to the stated assistive-function and law-enforcement exceptions. — Provider, GPAI model provider
- Art. 60(4) (k)The predictions, recommendations or decisions of the AI system used in real-world testing must be capable of being effectively reversed and disregarded. — Provider
- Art. 72(1)Providers of high-risk AI systems must establish and document a proportionate post-market monitoring system for the nature and risks of the system. — Provider
- Art. 72(2)Post-market monitoring must allow the provider to evaluate continuous compliance with Chapter III Section 2 requirements and, where relevant, interactions with other AI systems. — Provider
- Art. 72(2)The post-market monitoring system must actively and systematically collect, document and analyse relevant performance data throughout the high-risk AI system lifetime. — Provider
- Art. 72(3)The post-market monitoring system must be based on a plan that forms part of the Annex IV technical documentation. — Provider
- Art. 73(1)Providers of high-risk AI systems placed on the Union market must report any serious incident to the market surveillance authorities where the incident occurred. — Provider
- Art. 73(2)The serious-incident report must be made immediately after causal link or reasonable likelihood is established, and no later than 15 days after awareness. — Provider
- Art. 73(3)For a widespread infringement or an Article 3(49)(b) serious incident, the report must be immediate and no later than two days after awareness. — Provider
- Art. 73(4)Where a serious incident involves a death, the report must be immediate after causal relationship is established or suspected, and no later than 10 days after awareness. — Provider
- Art. 73(6)After reporting a serious incident, the provider must investigate without delay, including risk assessment of the incident and corrective action. — Provider
- Art. 74(12)Providers must grant market surveillance authorities full access to documentation and training, validation and testing data sets where relevant and necessary for their tasks. — Provider, Market surveillance authority
- Art. 74(13)Market surveillance authorities may access high-risk AI source code on reasoned request only when source access is necessary and other data, documentation and audit methods are exhausted or insufficient. — Provider, Market surveillance authority
- Art. 75(1a)Providers of high-risk AI systems supervised by the AI Office must report serious incidents to the AI Office, with Article 73(2) to (9) applying mutatis mutandis; the AI Office must transmit relevant information onward. — Provider, AI Office
- Art. 80(2)If the system is found high-risk, the provider must take necessary action to meet AI Act high-risk requirements and obligations and take corrective action within the prescribed period. — Provider
- Art. 80(4)Providers that fail to bring a reclassified high-risk system into compliance within the prescribed period are subject to fines and must correct all affected Union-market systems. — Provider
- Art. 80(7)Intentional misclassification to circumvent Chapter III Section 2 triggers Article 99 fines, and authorities may use EU database information for checks. — Provider, Market surveillance authority
- Art. 82(2)The provider or other relevant operator must ensure corrective action is taken for all affected Union-market systems within the authority-prescribed timeline. — Provider, Any operator
- Art. 83(1)When formal non-compliance is found, including CE marking, EU declaration, database registration, authorised-representative or technical-documentation failures, the authority must require the provider to end it. — Market surveillance authority, Provider
- Art. 111(4)Providers of AI systems, including GPAI systems, generating synthetic audio, image, video or text content placed on the market before 2 August 2026 must comply with Article 50(2) by 2 December 2026. — Provider, GPAI model provider
Penalties, rights, scope and transition
- Art. 2(7)Union personal-data, privacy and communications-confidentiality law continues to apply to personal data processed in connection with AI Act rights and obligations, subject to Articles 4a and 59. — Any operator, Union institution
- Art. 4(2)The Commission and Member States must support and facilitate provider and deployer efforts on AI literacy, and the Commission must publish practical compliance examples on the Article 62 platform. — Commission, Member State
- Art. 73(7)The Commission must develop dedicated serious-incident reporting guidance by 2 August 2025 and assess it regularly. — Commission
- Art. 73(7)When notified of an Article 3(49)(c) serious incident, the relevant market surveillance authority must inform the fundamental-rights authorities or bodies referred to in Article 77(1). — Market surveillance authority
- Art. 73(8)The market surveillance authority must take appropriate Regulation 2019/1020 measures within seven days of receiving a serious-incident notification and follow notification procedures. — Market surveillance authority
- Art. 73(11)National competent authorities must immediately notify the Commission of any serious incident, whether or not they have acted on it. — National competent authority
- Art. 74(8)For specified Annex III law-enforcement, border, justice and democracy systems, Member States must designate data-protection supervisory authorities or similarly conditioned authorities. — Member State, Market surveillance authority
- Art. 74(8)Market surveillance activities must not affect judicial independence or interfere with judicial authorities when they act in their judicial capacity. — Market surveillance authority
- Art. 74(14)Information and documentation obtained by market surveillance authorities under Article 74 must be treated under Article 78 confidentiality obligations. — Market surveillance authority
- Art. 75(1c)When AI Office investigatory or enforcement action in a Member State involves access to a public authority data or AI system, the relevant market surveillance authority must assist. — AI Office, Market surveillance authority
- Art. 75c(4)An AI Office non-compliance decision may be accompanied by penalties under Article 99(3) to (7), applied mutatis mutandis to AI Office supervision and enforcement. — AI Office, Any operator
- Art. 75c(5)The AI Office may impose periodic penalty payments to compel Article 75(1) operators to submit to investigations or inspections, comply with information requests, give correct explanations, carry out corrective actions, comply with commitments or comply with non-compliance decisions. — AI Office, Any operator
- Art. 77(1)National authorities or bodies supervising Union fundamental-rights obligations have power to request and access necessary AI Act information or documentation from the relevant market surveillance authority in accessible, machine-readable electronic form. — Other, Market surveillance authority
- Art. 77(3)Where documentation is insufficient to determine whether Union fundamental-rights obligations were infringed, the public authority or body may request technical testing and the market surveillance authority must organise it with close involvement of the requester. — Other, Market surveillance authority
- Art. 77(4)Information or documentation obtained by national fundamental-rights authorities or bodies under Article 77 must be treated under Article 78 confidentiality obligations. — Other
- Art. 77(1a)Subject to Article 77 conditions, the market surveillance authority must grant those public authorities or bodies access, including by requesting information from providers or deployers where necessary and without undue delay. — Market surveillance authority
- Art. 77(1b)Market surveillance authorities and fundamental-rights authorities must cooperate closely, provide mutual assistance and exchange necessary information to ensure coherent application and streamlined procedures. — Market surveillance authority, Other
- Art. 78(1)The Commission, market surveillance authorities, notified bodies and others applying the Act must respect confidentiality of information and data obtained in their tasks and activities. — Commission, Market surveillance authority, Notified body, Natural person, Other
- Art. 78(1)Confidentiality must protect intellectual property, trade secrets, effective enforcement, public and national security, criminal or administrative proceedings, and classified information. — Commission, Market surveillance authority, Notified body, Other
- Art. 78(2)Authorities applying the Act must request only strictly necessary data, protect obtained information with adequate and effective cybersecurity measures, and delete data when no longer needed. — Commission, Market surveillance authority, Notified body, National competent authority
- Art. 79(2)Where a Member State market surveillance authority has sufficient reason to consider an AI system risky, it must evaluate compliance, pay particular attention to vulnerable groups, cooperate with Article 77 bodies when fundamental-rights risks appear, and operators must cooperate as necessary. — Market surveillance authority, Any operator
- Art. 79(4)The operator must ensure all appropriate corrective action is taken for all AI systems concerned that it has made available on the Union market. — Any operator
- Art. 79(5)If the AI system operator fails to take adequate corrective action in time, the market surveillance authority must take provisional measures to prohibit, restrict, withdraw or recall the AI system and notify the Commission and other Member States. — Market surveillance authority
- Art. 79(8)If no objection is raised within three months, or within 30 days for Article 5 non-compliance, another authority provisional measure is deemed justified; market surveillance authorities must then ensure appropriate restrictive measures without undue delay. — Market surveillance authority, Commission
- Art. 80(1)Market surveillance authorities must evaluate AI systems classified by providers as non-high-risk when they have sufficient reason to consider the system is actually high-risk. — Market surveillance authority
- Art. 82(1)Even if a high-risk AI system complies with the Regulation, authorities must require measures if it still risks health, safety, fundamental rights or public interests. — Market surveillance authority, Any operator
- Art. 83(2)If formal non-compliance persists, the authority must take proportionate measures to restrict, prohibit, recall or withdraw the high-risk AI system without delay. — Market surveillance authority
- Art. 85Any natural or legal person with grounds to consider there has been an AI Act infringement may submit complaints to the relevant market surveillance authority. — Natural person, Other
- Art. 96(1)The Commission must develop guidelines on practical implementation of the Regulation, including high-risk requirements and obligations, prohibited practices, substantial modification, transparency duties, legal relationships and the AI-system definition. — Commission
- Art. 99(1)Member States must lay down rules on penalties and other enforcement measures for any AI Act infringement by operators and ensure effective implementation, with effective, proportionate and dissuasive penalties and attention to SMEs and SMCs. — Member State
- Art. 99(3)Non-compliance with Article 5 prohibited AI practices is subject to administrative fines up to EUR 35,000,000 or, for undertakings, 7% of total worldwide annual turnover, whichever is higher. — Any operator
- Art. 99(5)Supplying incorrect, incomplete or misleading information to notified bodies or national competent authorities in response to a request is subject to fines up to EUR 7,500,000 or 1% of worldwide turnover, whichever is higher. — Any operator
- Art. 99(6)For SMEs, including start-ups, each Article 99 fine is capped at the lower of the percentage or amount referred to in paragraphs 3, 4 and 5. — Any operator
- Art. 99(7)Authorities deciding whether to impose an administrative fine and its amount must consider all relevant circumstances, including gravity, duplicate penalties, size, aggravating or mitigating factors, cooperation, responsibility, notification, intent and mitigation. — Market surveillance authority, National competent authority
- Art. 99(9)Depending on national legal systems, administrative-fine rules may be applied by competent national courts or other bodies, with equivalent effect. — Member State, Other
- Art. 99(10)Exercise of Article 99 powers must be subject to appropriate procedural safeguards under Union and national law, including effective judicial remedies and due process. — Member State, National competent authority
- Art. 99(6a)For SMCs, each fine under Article 99(4) and (5) is capped at the lower of the percentage or amount stated in those paragraphs. — Any operator
- Art. 100(2)Union institutions, bodies, offices and agencies that breach Article 5 prohibited practices face administrative fines of up to EUR 1 500 000. — Union institution
- Art. 111(2)For other high-risk AI systems placed on the market or put into service before the Chapter III application date, the Regulation applies only if those systems are subject to significant design changes from that date. — Any operator
- Art. 112(1)The Commission must annually assess the need to amend Annex III and Article 5 prohibited-practice lists until the Article 97 delegation period ends, and submit findings to Parliament and Council. — Commission
- Art. 113Unless a specific amended Article 113 exception applies, the AI Act applies from 2 August 2026. — Any operator
- Art. 113 (Art. 113(a))Chapters I and II apply from 2 February 2025, except the newly specified Article 5(1) points and Article 5(1a) and (1b) later date. — Any operator
- Art. 113 (Art. 113(a) exception)Article 5(1) first-subparagraph points (ba) and (bb), and Article 5(1a) and (1b), apply from 2 December 2026 under amended Article 113(a). — Any operator
- Art. 113 (Art. 113(b))Chapter III Section 4, Chapter V, Chapter VII, Chapter XII and Article 78 apply from 2 August 2025, except Article 101. — Any operator
Fines, by tier
Articles 99–101 as written. "Whichever is higher" for most operators; for SMEs and start-ups Article 99(6) applies the lower of the two.
| Basis | Conduct | Who | Max fixed | % turnover | Rule |
|---|---|---|---|---|---|
| Art. 99(3) | non-compliance with the prohibition of the AI practices referred to in Article 5 | operators; undertakings are subject to the turnover alternative | €35m | 7 | whichever is higher |
| Art. 99(4) | non-compliance with listed operator or notified-body obligations other than Article 5 | providers, authorised representatives, importers, distributors, deployers and notified bodies | €15m | 3 | whichever is higher |
| Art. 99(5) | supply of incorrect, incomplete or misleading information to notified bodies or national competent authorities in reply to a request | operators or other addressees responding to notified bodies or national competent authorities; undertakings are subject to the turnover alternative | €7.5m | 1 | whichever is higher |
| Art. 99(6) | SME/start-up cap for each fine referred to in Article 99 | SMEs, including start-ups | — | — | whichever is lower (SMEs) |
| Art. 100(2) | non-compliance by Union institutions, bodies, offices and agencies with the prohibition of the AI practices referred to in Article 5 | Union institutions, bodies, offices and agencies falling within the scope of the Regulation; EDPS imposes the fine | €1.5m | — | whichever is higher |
| Art. 100(3) | non-compliance by Union institutions, bodies, offices and agencies with any other AI-system requirements or obligations under the Regulation | Union institutions, bodies, offices and agencies falling within the scope of the Regulation; EDPS imposes the fine | €0.75m | — | whichever is higher |
| Art. 101(1) | intentional or negligent infringement by providers of general-purpose AI models of relevant provisions, information/document requests, requested measures, or access for evaluations | providers of general-purpose AI models; Commission imposes the fine | €15m | 3 | whichever is higher |
| Art. 99(6a) | any infringement referred to in Article 99(4) or (5) committed by a small mid-cap enterprise (SMC) | small mid-cap enterprises (SMCs), Art. 3(14b) | — | — | whichever is lower (SMCs) — inserted by Regulation (EU) 2026/1744 |
| Art. 75c(4) | non-compliance found by the AI Office in respect of operators within its competence under Article 75(1) (certain AI systems built on general-purpose models or embedded in very large online platforms and search engines) | operators subject to AI Office supervision under Art. 75(1) | — | — | Article 99(3)–(7) tiers apply mutatis mutandis, imposed by the AI Office — inserted by Regulation (EU) 2026/1744 |
What each Member State has done
147 national instruments across 32 states — the implementing act, designated authorities, Article 99 penalty regime, Article 57 sandbox (deadline 2 August 2027 after the Omnibus), guidance reaching legal practice — one page per state, dated and sourced to the gazette or authority. The Commission has not yet published its consolidated list of market surveillance authorities; where a state has no verifiable instrument its page says what was checked and when. Read the September 2026 report on national implementation →
- Austriano implementing act found
- Belgiumno implementing act found
- Bulgariano implementing act found
- Croatiano implementing act found
- CyprusThe Artificial Intelligence Law of 2026 — draft · sandbox announced
- CzechiaDraft Act on Artificial Intelligence — draft
- DenmarkAct No. 467 of 14 May 2025 — in-force · sandbox operational
- Estoniano implementing act found
- FinlandAct on supervision of certain artificial intelligence systems — in-force · sandbox announced
- Franceno implementing act found
- GermanyAct implementing Regulation (EU) 2024/1689 — in-force · sandbox announced
- GreeceLaw 5321/2026 — in-force · sandbox announced
- HungaryAct LXXV of 2025 on artificial intelligence systems — in-force · sandbox announced
- IcelandIceland's AI Action Plan 2025-2027 — announced
- IrelandRegulation of Artificial Intelligence Act — in-force
- ItalyLaw No. 132 of 23 September 2025 — in-force · sandbox announced
- LatviaInformative report on implementing the AI Act requirements — draft · sandbox announced
- Liechtensteinno implementing act found
- LithuaniaAmendments to the Law on Technology and Innovation and the Law on Information Society Services — adopted · sandbox operational
- LuxembourgBill implementing certain provisions of Regulation (EU) 2024/1689 — bill · sandbox announced
- MaltaArtificial Intelligence (Designation of the Malta Digital Innovation Authority) Regulations, 2025 — in-force · sandbox designated
- NetherlandsAI Regulation Implementation Act — draft
- Norwayno implementing act found · sandbox announced
- PolandAct of 3 July 2026 on artificial intelligence systems — in-force · sandbox designated
- Portugalno implementing act found
- RomaniaArtificial Intelligence Act in Romania – current state of the implementation framework — draft
- Slovakiano implementing act found
- SloveniaAct implementing the EU regulation laying down harmonised rules on artificial intelligence — adopted · sandbox designated
- SpainOrganic Bill for the good use and governance of artificial intelligence — bill · sandbox operational
- SwedenAdaptations to the AI Regulation, SOU 2025:101 — draft
- Switzerlandno implementing act found
- United Kingdomno implementing act found
What the Digital Omnibus changed
72 articles amended or inserted by Regulation (EU) 2026/1744 (Digital Omnibus on AI), by how much the text changed. Each article page marks the change and shows the consolidated text; the word-level diff is in the dataset (amendments).
- Art. 75a Supervisory and enforcement powers of the AI Office new
- Art. 75c Non-compliance, fines and periodic penalty payments new
- Art. 60a Testing of high-risk AI systems covered by Union harmonisation legislation listed in Section B of Annex I in real-world conditions outside AI regulatory sandboxes new
- Art. 4a Processing of special categories of personal data for bias detection and correction new
- Art. 75d Safeguards and further specification new
- Art. 75b Commitments new
- Art. 5 Prohibited AI practices ~750 words
- Art. 75 Market surveillance and control of AI systems and mutual assistance ~725 words
- Art. 43 Conformity assessment ~428 words
- Art. 26 Obligations of deployers of high-risk AI systems ~391 words
- Art. 3 Definitions ~357 words
- Art. 57 AI regulatory sandboxes ~331 words
- Art. 10 Data and data governance ~314 words
- Art. 6 Classification rules for high-risk AI systems ~249 words
- Art. 2 Scope ~222 words
- Art. 66 Tasks of the Board ~204 words
- Art. 13 Transparency and provision of information to deployers ~201 words
- Art. 28 Notifying authorities ~188 words
- Art. 77 Powers of authorities protecting fundamental rights and cooperation with market surveillance authorities ~180 words
- Art. 25 Responsibilities along the AI value chain ~176 words
- Art. 15 Accuracy, robustness and cybersecurity ~165 words
- Art. 11 Technical documentation ~152 words
- Art. 79 Procedure at national level for dealing with AI systems presenting a risk ~143 words
- Art. 56 Codes of practice ~137 words
- Art. 96 Guidelines from the Commission on the implementation of this Regulation ~136 words
- Art. 50 Transparency obligations for providers and deployers of certain AI systems ~131 words
- Art. 4 AI literacy ~124 words
- Art. 9 Risk management system ~122 words
- Art. 40 Harmonised standards and standardisation deliverables ~117 words
- Art. 74 Market surveillance and control of AI systems in the Union market ~114 words
- Art. 36 Changes to notifications ~113 words
- Art. 111 AI systems already placed on the market or put into service and general-purpose AI models already placed on the marked ~110 words
- Art. 68 Scientific panel of independent experts ~107 words
- Art. 41 Common specifications ~105 words
- Art. 72 Post-market monitoring by providers and post-market monitoring plan for high-risk AI systems ~99 words
- Art. 78 Confidentiality ~99 words
- Art. 60 Testing of high-risk AI systems in real world conditions outside AI regulatory sandboxes ~96 words
- Art. 73 Reporting of serious incidents ~83 words
- Art. 113 Entry into force and application ~83 words
- Art. 59 Further processing of personal data for developing certain AI systems in the public interest in the AI regulatory sandbox ~75 words
- Art. 65 Establishment and structure of the European Artificial Intelligence Board ~72 words
- Art. 29 Application of a conformity assessment body for notification ~71 words
- Art. 108 Amendments to Regulation (EU) 2018/1139 ~62 words
- Art. 110 Amendment to Directive (EU) 2020/1828 ~62 words
- Art. 27 Fundamental rights impact assessment for high-risk AI systems ~61 words
- Art. 101 Fines for providers of general-purpose AI models ~61 words
- Art. 99 Penalties ~53 words
- Art. 58 Detailed arrangements for, and functioning of, AI regulatory sandboxes ~52 words
- Art. 69 Access to the pool of experts by the Member States ~49 words
- Art. 14 Human oversight ~45 words
- Art. 42 Presumption of conformity with certain requirements ~45 words
- Art. 53 Obligations for providers of general-purpose AI models ~44 words
- Art. 97 Exercise of the delegation ~39 words
- Art. 7 Amendments to Annex III ~32 words
- Art. 64 AI Office ~32 words
- Art. 49 Registration ~31 words
- Art. 52 Procedure ~30 words
- Art. 30 Notification procedure ~19 words
- Art. 44 Certificates ~17 words
- Art. 106 Amendment to Directive (EU) 2016/797 ~16 words
- Art. 107 Amendment to Regulation (EU) 2018/858 ~16 words
- Art. 109 Amendment to Regulation (EU) 2019/2144 ~16 words
- Art. 17 Quality management system ~15 words
- Art. 105 Amendment to Directive 2014/90/EU ~15 words
- Art. 63 Derogations for specific operators ~13 words
- Art. 1 Subject matter' ~10 words
- Art. 100 Administrative fines on Union institutions, bodies, offices and agencies ~4 words
- Art. 70 Designation of national competent authorities and single points of contact ~3 words
- Art. 102 Amendment to Regulation (EC) No 300/2008 ~3 words
- Art. 103 Amendment to Regulation (EU) No 167/2013 ~3 words
- Art. 104 Amendment to Regulation (EU) No 168/2013 ~3 words
- Art. 95 Codes of conduct for voluntary application of specific requirements ~2 words
All 119 articles
Each page carries the official text and the duties coded from it. Definitions are listed below.
Chapter I — Subject matter'
Chapter II — Prohibited AI practices
Chapter III — Classification rules for high-risk AI systems
- Art. 6 Classification rules for high-risk AI systems
- Art. 7 Amendments to Annex III
- Art. 8 Compliance with the requirements
- Art. 9 Risk management system
- Art. 10 Data and data governance
- Art. 11 Technical documentation
- Art. 12 Record-keeping
- Art. 13 Transparency and provision of information to deployers
- Art. 14 Human oversight
- Art. 15 Accuracy, robustness and cybersecurity
- Art. 16 Obligations of providers of high-risk AI systems
- Art. 17 Quality management system
- Art. 18 Documentation keeping
- Art. 19 Automatically generated logs
- Art. 20 Corrective actions and duty of information
- Art. 21 Cooperation with competent authorities
- Art. 22 Authorised representatives of providers of high-risk AI systems
- Art. 23 Obligations of importers
- Art. 24 Obligations of distributors
- Art. 25 Responsibilities along the AI value chain
- Art. 26 Obligations of deployers of high-risk AI systems
- Art. 27 Fundamental rights impact assessment for high-risk AI systems
- Art. 28 Notifying authorities
- Art. 29 Application of a conformity assessment body for notification
- Art. 30 Notification procedure
- Art. 31 Requirements relating to notified bodies
- Art. 32 Presumption of conformity with requirements relating to notified bodies
- Art. 33 Subsidiaries of notified bodies and subcontracting
- Art. 34 Operational obligations of notified bodies
- Art. 35 Identification numbers and lists of notified bodies
- Art. 36 Changes to notifications
- Art. 37 Challenge to the competence of notified bodies
- Art. 38 Coordination of notified bodies
- Art. 39 Conformity assessment bodies of third countries
- Art. 40 Harmonised standards and standardisation deliverables
- Art. 41 Common specifications
- Art. 42 Presumption of conformity with certain requirements
- Art. 43 Conformity assessment
- Art. 44 Certificates
- Art. 45 Information obligations of notified bodies
- Art. 46 Derogation from conformity assessment procedure
- Art. 47 EU declaration of conformity
- Art. 48 CE marking
- Art. 49 Registration
Chapter IV — Transparency obligations for providers and deployers of certain AI systems
Chapter V — Classification of general-purpose AI models as general-purpose AI models with systemic risk
- Art. 51 Classification of general-purpose AI models as general-purpose AI models with systemic risk
- Art. 52 Procedure
- Art. 53 Obligations for providers of general-purpose AI models
- Art. 54 Authorised representatives of providers of general-purpose AI models
- Art. 55 Obligations of providers of general-purpose AI models with systemic risk
- Art. 56 Codes of practice
Chapter VI — AI regulatory sandboxes
- Art. 57 AI regulatory sandboxes
- Art. 58 Detailed arrangements for, and functioning of, AI regulatory sandboxes
- Art. 59 Further processing of personal data for developing certain AI systems in the public interest in the AI regulatory sandbox
- Art. 60 Testing of high-risk AI systems in real world conditions outside AI regulatory sandboxes
- Art. 60a Testing of high-risk AI systems covered by Union harmonisation legislation listed in Section B of Annex I in real-world conditions outside AI regulatory sandboxes
- Art. 61 Informed consent to participate in testing in real world conditions outside AI regulatory sandboxes
- Art. 62 Measures for providers and deployers, in particular SMEs, including start-ups
- Art. 63 Derogations for specific operators
Chapter VII — AI Office
- Art. 64 AI Office
- Art. 65 Establishment and structure of the European Artificial Intelligence Board
- Art. 66 Tasks of the Board
- Art. 67 Advisory forum
- Art. 68 Scientific panel of independent experts
- Art. 69 Access to the pool of experts by the Member States
- Art. 70 Designation of national competent authorities and single points of contact
Chapter VIII — EU database for high-risk AI systems listed in Annex III
Chapter IX — Post-market monitoring by providers and post-market monitoring plan for high-risk AI systems
- Art. 72 Post-market monitoring by providers and post-market monitoring plan for high-risk AI systems
- Art. 73 Reporting of serious incidents
- Art. 74 Market surveillance and control of AI systems in the Union market
- Art. 75 Market surveillance and control of AI systems and mutual assistance
- Art. 75a Supervisory and enforcement powers of the AI Office
- Art. 75b Commitments
- Art. 75c Non-compliance, fines and periodic penalty payments
- Art. 75d Safeguards and further specification
- Art. 76 Supervision of testing in real world conditions by market surveillance authorities
- Art. 77 Powers of authorities protecting fundamental rights and cooperation with market surveillance authorities
- Art. 78 Confidentiality
- Art. 79 Procedure at national level for dealing with AI systems presenting a risk
- Art. 80 Procedure for dealing with AI systems classified by the provider as non-high-risk in application of Annex III
- Art. 81 Union safeguard procedure
- Art. 82 Compliant AI systems which present a risk
- Art. 83 Formal non-compliance
- Art. 84 Union AI testing support structures
- Art. 85 Right to lodge a complaint with a market surveillance authority
- Art. 86 Right to explanation of individual decision-making
- Art. 87 Reporting of infringements and protection of reporting persons
- Art. 88 Enforcement of the obligations of providers of general-purpose AI models
- Art. 89 Monitoring actions
- Art. 90 Alerts of systemic risks by the scientific panel
- Art. 91 Power to request documentation and information
- Art. 92 Power to conduct evaluations
- Art. 93 Power to request measures
- Art. 94 Procedural rights of economic operators of the general-purpose AI model
Chapter X — Codes of conduct for voluntary application of specific requirements
Chapter XI — Exercise of the delegation
Chapter XII — Penalties
Chapter XIII — Amendment to Regulation (EC) No 300/2008
- Art. 102 Amendment to Regulation (EC) No 300/2008
- Art. 103 Amendment to Regulation (EU) No 167/2013
- Art. 104 Amendment to Regulation (EU) No 168/2013
- Art. 105 Amendment to Directive 2014/90/EU
- Art. 106 Amendment to Directive (EU) 2016/797
- Art. 107 Amendment to Regulation (EU) 2018/858
- Art. 108 Amendments to Regulation (EU) 2018/1139
- Art. 109 Amendment to Regulation (EU) 2019/2144
- Art. 110 Amendment to Directive (EU) 2020/1828
- Art. 111 AI systems already placed on the market or put into service and general-purpose AI models already placed on the marked
- Art. 112 Evaluation and review
- Art. 113 Entry into force and application
The 70 definitions (Article 3)
- (1) AI system
- a machine-based system that is designed to operate with varying levels of autonomy and that may exhibit adaptiveness after deployment, and that, for explicit or implicit objectives, infers, from the input it receives, how to generate outputs such as predictions, content, recommendations, or decisions that can influence physical or virtual environments
- (2) risk
- the combination of the probability of an occurrence of harm and the severity of that harm
- (3) provider
- a natural or legal person, public authority, agency or other body that develops an AI system or a general-purpose AI model or that has an AI system or a general-purpose AI model developed and places it on the market or puts the AI system into service under its own name or trademark, whether for payment or free of charge
- (4) deployer
- a natural or legal person, public authority, agency or other body using an AI system under its authority except where the AI system is used in the course of a personal non-professional activity
- (5) authorised representative
- a natural or legal person located or established in the Union who has received and accepted a written mandate from a provider of an AI system or a general-purpose AI model to, respectively, perform and carry out on its behalf the obligations and procedures established by this Regulation
- (6) importer
- a natural or legal person located or established in the Union that places on the market an AI system that bears the name or trademark of a natural or legal person established in a third country
- (7) distributor
- a natural or legal person in the supply chain, other than the provider or the importer, that makes an AI system available on the Union market
- (8) operator
- a provider, product manufacturer, deployer, authorised representative, importer or distributor
- (9) placing on the market
- the first making available of an AI system or a general-purpose AI model on the Union market
- (10) making available on the market
- the supply of an AI system or a general-purpose AI model for distribution or use on the Union market in the course of a commercial activity, whether in return for payment or free of charge
- (11) putting into service
- the supply of an AI system for first use directly to the deployer or for own use in the Union for its intended purpose
- (12) intended purpose
- the use for which an AI system is intended by the provider, including the specific context and conditions of use, as specified in the information supplied by the provider in the instructions for use, promotional or sales materials and statements, as well as in the technical documentation
- (13) reasonably foreseeable misuse
- the use of an AI system in a way that is not in accordance with its intended purpose, but which may result from reasonably foreseeable human behaviour or interaction with other systems, including other AI systems
- (14) safety component
- a component of a product or of an AI system which fulfils a safety function for that product or AI system, or the failure or malfunctioning of which endangers the health and safety of persons or property; for the purposes of this definition, a component fulfils a safety function where its intended purpose is to prevent or mitigate risks to health and safety of persons or property
- (14a) micro, small and medium-sized enterprise’ or ‘SME
- a micro, small or medium-sized enterprise as defined in Article 2 of the Annex to Recommendation 2003/361/EC
- (14b) small mid-cap enterprise’ or ‘SMC
- a small mid-cap enterprise as defined in point (2) of the Annex to Recommendation (EU) 2025/1099
- (15) instructions for use
- the information provided by the provider to inform the deployer of, in particular, an AI system’s intended purpose and proper use
- (16) recall of an AI system
- any measure aiming to achieve the return to the provider or taking out of service or disabling the use of an AI system made available to deployers
- (17) withdrawal of an AI system
- any measure aiming to prevent an AI system in the supply chain being made available on the market
- (18) performance of an AI system
- the ability of an AI system to achieve its intended purpose
- (19) notifying authority
- the national authority responsible for setting up and carrying out the necessary procedures for the assessment, designation and notification of conformity assessment bodies and for their monitoring
- (20) conformity assessment
- the process of demonstrating whether the requirements set out in Chapter III, Section 2 relating to a high-risk AI system have been fulfilled
- (21) conformity assessment body
- a body that performs third-party conformity assessment activities, including testing, certification and inspection
- (22) notified body
- a conformity assessment body notified in accordance with this Regulation and other relevant Union harmonisation legislation
- (23) substantial modification
- a change to an AI system after its placing on the market or putting into service which is not foreseen or planned in the initial conformity assessment carried out by the provider and as a result of which the compliance of the AI system with the requirements set out in Chapter III, Section 2 is affected or results in a modification to the intended purpose for which the AI system has been assessed
- (24) CE marking
- a marking by which a provider indicates that an AI system is in conformity with the requirements set out in Chapter III, Section 2 and other applicable Union harmonisation legislation providing for its affixing
- (25) post-market monitoring system
- all activities carried out by providers of AI systems to collect and review experience gained from the use of AI systems they place on the market or put into service for the purpose of identifying any need to immediately apply any necessary corrective or preventive actions
- (26) market surveillance authority
- the national authority carrying out the activities and taking the measures pursuant to Regulation (EU) 2019/1020
- (27) harmonised standard
- a harmonised standard as defined in Article 2(1), point (c), of Regulation (EU) No 1025/2012
- (28) common specification
- a set of technical specifications as defined in Article 2, point (4) of Regulation (EU) No 1025/2012, providing means to comply with certain requirements established under this Regulation
- (29) training data
- data used for training an AI system through fitting its learnable parameters
- (30) validation data
- data used for providing an evaluation of the trained AI system and for tuning its non-learnable parameters and its learning process in order, inter alia, to prevent underfitting or overfitting
- (31) validation data set
- a separate data set or part of the training data set, either as a fixed or variable split
- (32) testing data
- data used for providing an independent evaluation of the AI system in order to confirm the expected performance of that system before its placing on the market or putting into service
- (33) input data
- data provided to or directly acquired by an AI system on the basis of which the system produces an output
- (34) biometric data
- personal data resulting from specific technical processing relating to the physical, physiological or behavioural characteristics of a natural person, such as facial images or dactyloscopic data
- (35) biometric identification
- the automated recognition of physical, physiological, behavioural, or psychological human features for the purpose of establishing the identity of a natural person by comparing biometric data of that individual to biometric data of individuals stored in a database
- (36) biometric verification
- the automated, one-to-one verification, including authentication, of the identity of natural persons by comparing their biometric data to previously provided biometric data
- (37) special categories of personal data
- the categories of personal data referred to in Article 9(1) of Regulation (EU) 2016/679, Article 10 of Directive (EU) 2016/680 and Article 10(1) of Regulation (EU) 2018/1725
- (38) sensitive operational data
- operational data related to activities of prevention, detection, investigation or prosecution of criminal offences, the disclosure of which could jeopardise the integrity of criminal proceedings
- (39) emotion recognition system
- an AI system for the purpose of identifying or inferring emotions or intentions of natural persons on the basis of their biometric data
- (40) biometric categorisation system
- an AI system for the purpose of assigning natural persons to specific categories on the basis of their biometric data, unless it is ancillary to another commercial service and strictly necessary for objective technical reasons
- (41) remote biometric identification system
- an AI system for the purpose of identifying natural persons, without their active involvement, typically at a distance through the comparison of a person’s biometric data with the biometric data contained in a reference database
- (42) real-time remote biometric identification system
- a remote biometric identification system, whereby the capturing of biometric data, the comparison and the identification all occur without a significant delay, comprising not only instant identification, but also limited short delays in order to avoid circumvention
- (43) post-remote biometric identification system
- a remote biometric identification system other than a real-time remote biometric identification system
- (44) publicly accessible space
- any publicly or privately owned physical place accessible to an undetermined number of natural persons, regardless of whether certain conditions for access may apply, and regardless of the potential capacity restrictions
- (45) law enforcement authority
- (a) any public authority competent for the prevention, investigation, detection or prosecution of criminal offences or the execution of criminal penalties, including the safeguarding against and the prevention of threats to public security; or (b) any other body or entity entrusted by Member State law to exercise public authority and public powers for the purposes of the prevention, investigation, detection or prosecution of criminal offences or the execution of criminal penalties, including the safeguarding against and the prevention of threats to public security
- (46) law enforcement
- activities carried out by law enforcement authorities or on their behalf for the prevention, investigation, detection or prosecution of criminal offences or the execution of criminal penalties, including safeguarding against and preventing threats to public security
- (47) AI Office
- the Commission’s function of contributing to the implementation, monitoring and supervision of AI systems and general-purpose AI models, and AI governance, provided for in Commission Decision of 24 January 2024; references in this Regulation to the AI Office shall be construed as references to the Commission
- (48) national competent authority
- a notifying authority or a market surveillance authority; as regards AI systems put into service or used by Union institutions, agencies, offices and bodies, references to national competent authorities or market surveillance authorities in this Regulation shall be construed as references to the European Data Protection Supervisor
- (49) serious incident
- an incident or malfunctioning of an AI system that directly or indirectly leads to any of the following: (a) the death of a person, or serious harm to a person’s health; (b) a serious and irreversible disruption of the management or operation of critical infrastructure; (c) the infringement of obligations under Union law intended to protect fundamental rights; (d) serious harm to property or the environment
- (50) personal data
- personal data as defined in Article 4, point (1), of Regulation (EU) 2016/679
- (51) non-personal data
- data other than personal data as defined in Article 4, point (1), of Regulation (EU) 2016/679
- (52) profiling
- profiling as defined in Article 4, point (4), of Regulation (EU) 2016/679
- (53) real-world testing plan
- a document that describes the objectives, methodology, geographical, population and temporal scope, monitoring, organisation and conduct of testing in real-world conditions
- (54) sandbox plan
- a document agreed between the participating provider and the competent authority describing the objectives, conditions, timeframe, methodology and requirements for the activities carried out within the sandbox
- (55) AI regulatory sandbox
- a controlled framework set up by a competent authority which offers providers or prospective providers of AI systems the possibility to develop, train, validate and test, where appropriate in real-world conditions, an innovative AI system, pursuant to a sandbox plan for a limited time under regulatory supervision
- (56) AI literacy
- skills, knowledge and understanding that allow providers, deployers and affected persons, taking into account their respective rights and obligations in the context of this Regulation, to make an informed deployment of AI systems, as well as to gain awareness about the opportunities and risks of AI and possible harm it can cause
- (57) testing in real-world conditions
- the temporary testing of an AI system for its intended purpose in real-world conditions outside a laboratory or otherwise simulated environment, with a view to gathering reliable and robust data and to assessing and verifying the conformity of the AI system with the requirements of this Regulation and it does not qualify as placing the AI system on the market or putting it into service within the meaning of this Regulation, provided that all the conditions laid down in Article 57 or 60 are fulfilled
- (58) subject
- a natural person who participates in testing in real-world conditions
- (59) informed consent
- a subject’s freely given, specific, unambiguous and voluntary expression of his or her willingness to participate in a particular testing in real-world conditions, after having been informed of all aspects of the testing that are relevant to the subject’s decision to participate
- (60) deep fake
- AI-generated or manipulated image, audio or video content that resembles existing persons, objects, places, entities or events and would falsely appear to a person to be authentic or truthful
- (61) widespread infringement
- any act or omission contrary to Union law protecting the interest of individuals, which: (a) has harmed or is likely to harm the collective interests of individuals residing in at least two Member States other than the Member State in which: (i) the act or omission originated or took place; (ii) the provider concerned, or, where applicable, its authorised representative is located or established; or (iii) the deployer is established, when the infringement is committed by the deployer; (b) has caused, causes or is likely to cause harm to the collective interests of individuals and has common features, including the same unlawful practice or the same interest being infringed, and is occurring concurrently, committed by the same operator, in at least three Member States
- (62) critical infrastructure
- critical infrastructure as defined in Article 2, point (4), of Directive (EU) 2022/2557
- (63) general-purpose AI model
- an AI model, including where such an AI model is trained with a large amount of data using self-supervision at scale, that displays significant generality and is capable of competently performing a wide range of distinct tasks regardless of the way the model is placed on the market and that can be integrated into a variety of downstream systems or applications, except AI models that are used for research, development or prototyping activities before they are placed on the market
- (64) high-impact capabilities
- capabilities that match or exceed the capabilities recorded in the most advanced general-purpose AI models
- (65) systemic risk
- a risk that is specific to the high-impact capabilities of general-purpose AI models, having a significant impact on the Union market due to their reach, or due to actual or reasonably foreseeable negative effects on public health, safety, public security, fundamental rights, or the society as a whole, that can be propagated at scale across the value chain
- (66) general-purpose AI system
- an AI system which is based on a general-purpose AI model and which has the capability to serve a variety of purposes, both for direct use as well as for integration in other AI systems
- (67) floating-point operation
- any mathematical operation or assignment involving floating-point numbers, which are a subset of the real numbers typically represented on computers by an integer of fixed precision scaled by an integer exponent of a fixed base
- (68) downstream provider
- a provider of an AI system, including a general-purpose AI system, which integrates an AI model, regardless of whether the AI model is provided by themselves and vertically integrated or provided by another entity based on contractual relations
Cite
SafeLegalAI (published by Cognesio LLP), "EU AI Act, structured", safelegalai.com/regulation/eu-ai-act, accessed 2026-09-08. Coding CC BY 4.0; text © European Union, consolidated version of 27 July 2026 (https://eur-lex.europa.eu/eli/reg/2024/1689/2026-07-27/eng), reused under Commission Decision 2011/833/EU. Only the Official Journal text is authentic.