The AI Act — Regulation (EU) 2024/1689 — is the first comprehensive law governing artificial intelligence systems. It entered into force on 1 August 2024 and applies in phases, not all at once.
The short answer
The AI Act — Regulation (EU) 2024/1689 — is the first comprehensive law governing artificial intelligence systems. It entered into force on **1 August 2024** and applies in **phases**, not all at once.
It does not regulate AI as a technology. **It regulates AI by use case and by role.** The same model can be unregulated in one product and high-risk in another, depending on what it decides and about whom.
``` 2 February 2025 prohibited practices (Article 5) and AI literacy (Article 4) 2 August 2025 general-purpose AI model obligations, governance, most penalties 2 August 2026 general application, including Annex III high-risk systems and the Article 50 transparency duties 2 August 2027 high-risk systems that are products or safety components under Annex I sectoral legislation ```
**Two of these dates have already passed.** The prohibitions have been enforceable since February 2025, and they carry the regulation's highest penalty tier.
The four risk tiers
**Unacceptable risk — prohibited outright, Article 5**
Eight practices are banned. Among them: manipulative or deceptive techniques that materially distort behaviour; exploitation of vulnerabilities due to age, disability or social or economic situation; social scoring leading to detrimental treatment in unrelated contexts; untargeted scraping of facial images to build facial recognition databases; **emotion inference in the workplace and in education**, save for medical or safety purposes; and biometric categorisation to infer sensitive attributes.
**Emotion inference at work is the prohibition most likely to be breached unknowingly**, because it can arrive inside a bought product — an interview analysis tool, a call-centre sentiment feature, a productivity monitor — rather than through a decision to build one.
**High risk — permitted with conditions**
Two routes into the high-risk tier:
covered by EU sectoral legislation;
critical infrastructure, education and vocational training, employment and worker management, access to essential services, law enforcement, migration and border control, and the administration of justice.
Providers of high-risk systems must operate a risk management system, meet data governance requirements, produce technical documentation, ensure record-keeping through automatic logs, provide information to deployers, enable human oversight, and achieve appropriate accuracy, robustness and cybersecurity.
**Deployers have their own obligations**, and this is where most organisations sit. Using a high-risk system in employment or in access to services carries duties independent of the provider's — including human oversight, monitoring, and in defined cases a **fundamental rights impact assessment** before first use.
**Limited risk — transparency, Article 50**
Certain systems must disclose. People must be told when they are interacting with an AI system unless it is obvious; synthetic audio, image, video and text must be marked in a machine-readable format; deep fakes and AI-generated text published to inform the public on matters of public interest must be disclosed.
**Minimal risk — no obligations**
Everything else. **Most AI in commercial use sits here** — and the point of the classification exercise is to be able to demonstrate that, not to assume it.
- **Annex I** — the AI system is a product, or a safety component of a product, already
- **Annex III** — the AI system falls within a listed use case, including biometrics,
Who you are decides what you owe
The regulation assigns duties to **providers**, **deployers**, **importers**, **distributors**, **product manufacturers** and **authorised representatives**.
**The role is not fixed.** A deployer that puts its own name or trademark on a high-risk system, makes a substantial modification to it, or changes its intended purpose so that it becomes high-risk, **takes on the obligations of a provider**.
This is the clause that catches integrators and resellers. Rebranding a third-party model into your own product is not a commercial decision with a compliance footnote — it is a change of legal role.
**It reaches beyond the EU**
The regulation applies to providers placing systems on the Union market wherever they are established, and to providers and deployers established outside the Union **where the output produced by the system is used in the Union**. Output, not deployment, is the connecting factor.
General-purpose AI models
Providers of general-purpose AI models carry a distinct set of duties: technical documentation, information to downstream providers who integrate the model, a policy to comply with Union copyright law, and a **sufficiently detailed summary of the content used for training**.
Models presenting **systemic risk** carry additional duties — model evaluation including adversarial testing, assessment and mitigation of systemic risks, serious incident tracking and reporting, and an adequate level of cybersecurity protection.
**Downstream integrators are affected even though these obligations are not theirs.** The documentation the model provider supplies is the input to your own conformity work; if it is thin, your high-risk assessment is built on it anyway.
Penalties — Article 99
``` breach of the Article 5 prohibitions up to EUR 35 000 000 or 7 % of total worldwide annual turnover breach of most other obligations up to EUR 15 000 000 or 3 % supplying incorrect, incomplete or misleading information to notified bodies or national competent authorities up to EUR 7 500 000 or 1 % ```
Amounts are the **higher** of the two figures. For SMEs, including start-ups, the ceiling is the **lower** of the two.
**Seven per cent is the highest penalty ceiling in EU digital regulation** — above the GDPR's four per cent — and it attaches to the tier that has been enforceable since February 2025.
What to establish first
1. **Inventory the AI systems you provide and the ones you use.** Deployer obligations are the ones organisations discover late, because bought software is rarely inventoried as AI. 2. **Screen for Article 5 before anything else.** It is in force, it carries the highest penalty, and a prohibited practice cannot be remediated by documentation. 3. **Classify by use case, not by model.** The same model is minimal risk in one product and high risk in another. 4. **Check whether you have become a provider** by rebranding, modifying or repurposing someone else's system. 5. **Work the August 2026 date now for Annex III systems.** A fundamental rights impact assessment and a risk management system are not documents that can be produced in the final quarter.
Tools available on NexCyber
- Free applicability assessment — confirm AI Act role and risk tier
- Compliance responsibility mapper — RACI by role
- Penalty calculator — exposure by regulation
Further reading
→ AI Act risk tiers explained → Article 5 prohibited practices in force since February 2025 → AI Act × CRA — what overlaps for AI products with digital elements → One evidence set across five EU regulations → AI Act regulation overview
*This is regulatory information, not legal advice, and nothing here constitutes a compliance guarantee. The AI Act applies in phases, and harmonised standards, guidelines and codes of practice supporting it continue to be adopted — verify against the current text of Regulation (EU) 2024/1689 and the Official Journal. Consult your competent authority or a qualified adviser.*
This is an educational explainer. For the canonical regulation reference, see the dedicated AI Act page — or run an assessment to see how it applies to your product.