The EU AI Act, as an obligation list you can work from.
Regulation (EU) 2024/1689 is the first horizontal AI law in the world. This page is the working reference our advisory team uses with clients: which tier a system falls into, what each date actually triggers, which article demands which artefact, and what the nine parts of Annex IV ask for.
Last reviewed 6 September 2026. This is a practitioner's summary, not legal advice, and it is not a substitute for the consolidated text. A Commission proposal tabled in November 2025 would amend parts of the timetable; check its current status before relying on a date below.
The four risk tiers, and what each one costs you
The Act regulates uses, not technologies. The same model can sit in three tiers depending on what it is put to work on, so classification starts from the intended purpose — never from the architecture.
| Tier | Typical scope | Consequence |
|---|---|---|
Unacceptable Art. 5 | Social scoring by public or private actors, untargeted scraping of facial images, emotion inference in the workplace and in education, certain biometric categorisation, and — outside narrow law-enforcement exceptions — real-time remote biometric identification in publicly accessible spaces. | Prohibited. In force since 2 February 2025. |
High-risk · Annex III Art. 6(2) | Biometrics, critical infrastructure, education and vocational training, employment and worker management, access to essential private and public services including creditworthiness and life or health insurance pricing, law enforcement, migration and border control, administration of justice. | Full Chapter III obligation set. Applies since 2 August 2026. |
High-risk · Annex I Art. 6(1) | AI used as a safety component of, or itself a product covered by, existing EU product legislation that requires third-party conformity assessment — machinery, medical devices, lifts, toys, in-vitro diagnostics and others. | Same obligation set, applying from 2 August 2027. |
Transparency risk Art. 50 | Systems that interact directly with people, emotion recognition and biometric categorisation systems, and systems generating synthetic audio, image, video or text — including deep fakes. | Disclosure to the person, machine-readable marking of synthetic content, and labelling of deep fakes. |
Minimal risk Art. 95 | Everything else — spam filters, inventory forecasting, most recommendation and productivity tooling. | No mandatory obligations. Voluntary codes of conduct are encouraged. |
Which obligations apply from when
- 1 Aug 2024
Regulation (EU) 2024/1689 enters into force.
Art. 113
- 2 Feb 2025
Prohibited practices apply. The AI literacy duty in Article 4 applies to providers and deployers alike.
Art. 113(a)
- 2 Aug 2025
Obligations for general-purpose AI models, the governance and notifying-authority framework, confidentiality and most penalty provisions apply.
Art. 113(b)
- 2 Aug 2026
General application date: Annex III high-risk obligations and the Article 50 transparency duties apply.
Art. 113
- 2 Aug 2027
High-risk systems that are safety components of products regulated under Annex I, and GPAI models placed on the market before 2 August 2025.
Art. 113(c)
- 2 Aug 2030
AI systems used by public authorities that were placed on the market before 2 August 2026 must be brought into compliance.
Art. 111(2)
Article 111 treats systems already on the market differently: a high-risk system placed on the market before 2 August 2026 falls in scope only if its design changes significantly after that date — except where it is used by a public authority, which has until 2 August 2030 regardless.
Every high-risk obligation, and the artefact that evidences it
The distance between "we comply" and "we can show we comply" is this table. Each row is a duty in Chapter III, Section 2 and the record an auditor will ask to see.
| Article | Duty | What the evidence looks like |
|---|---|---|
| Art. 9 | Risk management system | A documented, iterative risk file maintained across the lifecycle — not a one-off assessment. |
| Art. 10 | Data and data governance | Dataset provenance, design choices, preparation steps, and an examination for possible biases and their mitigation. |
| Art. 11 · Annex IV | Technical documentation | The nine-part technical file, drawn up before market placement and kept current. |
| Art. 12 | Record-keeping | Automatically generated logs, technically enabled for the lifetime of the system. |
| Art. 13 | Transparency for deployers | Instructions for use stating capabilities, limitations, accuracy levels and oversight measures. |
| Art. 14 | Human oversight | Oversight measures designed into the system, plus evidence that the assigned humans have the competence and authority to act. |
| Art. 15 | Accuracy, robustness, cybersecurity | Declared accuracy metrics, adversarial and robustness testing, and resilience measures against model-specific attacks. |
| Art. 17 | Quality management system | A written QMS covering the regulatory strategy, design control, testing, data management and post-market monitoring. |
| Art. 43 | Conformity assessment | Internal control under Annex VI, or a notified body under Annex VII where the system involves biometrics and no harmonised standard was applied in full. |
| Art. 47 · 48 | EU declaration of conformity and CE marking | A signed declaration kept for ten years and the CE marking affixed. |
| Art. 49 | Registration | Registration of the system in the EU database before market placement. |
| Art. 72 | Post-market monitoring | A monitoring plan and the field data collected under it. |
| Art. 73 | Serious incident reporting | Reporting to the market surveillance authority immediately and no later than 15 days after becoming aware — 2 days where a widespread infringement or a serious and irreversible disruption of critical infrastructure is involved, and 10 days in the event of a death. |
What the technical file has to contain
Article 11 requires the technical documentation to exist before the system is placed on the market and to be kept up to date. Annex IV lists what it holds:
- 01A general description of the system: intended purpose, provider, versions, how it interacts with hardware and other software, and the instructions for use.
- 02A detailed description of the development process: methods and steps, third-party tools, design specifications, system architecture, data requirements and datasheets, human oversight measures, predetermined changes, and the validation and testing procedures with the metrics used.
- 03Detailed information on monitoring, functioning and control: capabilities and limitations, expected accuracy levels, foreseeable unintended outcomes, and input data specifications.
- 04A description of why the chosen performance metrics are appropriate for this system.
- 05The risk management system required by Article 9.
- 06A description of relevant changes made through the system's lifecycle.
- 07The harmonised standards applied, or a description of the other solutions adopted to meet the requirements.
- 08A copy of the EU declaration of conformity.
- 09The post-market monitoring plan required by Article 72.
Most of this is written by a person, months after the fact, from memory. Six of the nine parts describe things only the running system and its pipeline can evidence — which is the argument for generating the file from the pipeline rather than assembling it afterwards. How ComplianceEngine does it.
Provider or deployer — the distinction that decides your workload
A provider develops an AI system, or has one developed, and places it on the market or puts it into service under its own name or trademark. A deployer uses one under its own authority in a professional capacity. Providers carry the bulk of the high-risk duties; deployers carry the set in Article 26.
The trap in Article 25. A deployer becomes a provider — with the full obligation set, retroactively — in three situations: it puts its own name or trademark on a high-risk system already on the market, it substantially modifies one, or it changes the intended purpose of a system so that the system becomes high-risk. Fine-tuning a vendor model for hiring decisions is the everyday version of this.
The deployer's own duties
- Use the system in accordance with the instructions for use (Art. 26(1)).
- Assign human oversight to people with the necessary competence, training and authority (Art. 26(2)).
- Ensure input data is relevant and sufficiently representative for the intended purpose, where the deployer controls it (Art. 26(4)).
- Monitor operation, suspend use and inform the provider and the authority where a risk emerges (Art. 26(5)).
- Keep the automatically generated logs for at least six months (Art. 26(6)).
- Inform workers' representatives and affected workers before putting a high-risk system into use in the workplace (Art. 26(7)).
- Carry out a fundamental rights impact assessment where Article 27 applies — public bodies, private entities providing public services, and deployers of creditworthiness and life or health insurance pricing systems.
What non-compliance costs
| Breach | Maximum fine |
|---|---|
| Prohibited practice under Article 5 | €35 million or 7% of total worldwide annual turnover, whichever is higher |
| Most other obligations, including the high-risk provider and deployer duties | €15 million or 3% |
| Incorrect, incomplete or misleading information to notified bodies or authorities | €7.5 million or 1% |
Article 99(6): for SMEs and start-ups, each band is capped at the lower of the two figures rather than the higher.
Questions we are asked in the first meeting
Does the EU AI Act apply to a company based outside the EU?
Yes, in three cases. Article 2 extends the Regulation to providers who place an AI system on the EU market or put it into service in the EU regardless of where they are established, to deployers established in the EU, and to providers and deployers in third countries where the output produced by the system is used in the Union. A US company whose model scores job applicants for an EU employer is therefore in scope.
Is a CV-screening or candidate-ranking tool high-risk under the EU AI Act?
Almost always yes. Annex III, point 4 lists AI systems intended to be used for recruitment or selection — in particular to place targeted job advertisements, analyse and filter applications, and evaluate candidates — as high-risk. The narrow exemption in Article 6(3), for systems performing a purely preparatory or narrow procedural task, rarely covers ranking or filtering, and a provider relying on it must document the assessment and register the system anyway.
What is Annex IV of the EU AI Act, and who has to produce it?
Annex IV sets out the technical documentation a provider of a high-risk AI system must draw up before that system is placed on the market and keep up to date afterwards, as required by Article 11. It has nine parts, covering the system description, the development process and datasets, monitoring and control, performance metrics, the risk management system, lifecycle changes, the standards applied, the EU declaration of conformity, and the post-market monitoring plan.
What is the difference between a provider and a deployer under the EU AI Act?
A provider develops an AI system, or has one developed, and places it on the market or puts it into service under its own name or trademark. A deployer uses an AI system under its own authority in a professional capacity. Providers carry the bulk of the obligations for high-risk systems; deployers carry the narrower set in Article 26. Article 25 turns a deployer into a provider — with the full obligation set — if it puts its own name or trademark on a high-risk system, substantially modifies one, or changes the intended purpose of a system so that it becomes high-risk.
When did the high-risk obligations of the EU AI Act start to apply?
The Regulation entered into force on 1 August 2024 and applies in stages. Prohibited practices and the AI literacy duty applied from 2 February 2025, the general-purpose AI model obligations from 2 August 2025, and the general application date — which covers the Annex III high-risk systems and the Article 50 transparency duties — was 2 August 2026. High-risk AI systems that are safety components of products already regulated under Annex I follow on 2 August 2027.
What are the fines for non-compliance with the EU AI Act?
Article 99 sets three bands. Deploying a prohibited practice can be fined up to €35 million or 7% of total worldwide annual turnover, whichever is higher. Breaching most other obligations — including the high-risk provider and deployer duties — can be fined up to €15 million or 3%. Supplying incorrect, incomplete or misleading information to authorities or notified bodies can be fined up to €7.5 million or 1%. For SMEs and start-ups, each band is capped at the lower of the two figures.
More on the full FAQ, or how the Act relates to ISO/IEC 42001 certification.
Not sure which tier your systems fall into?
A 30-minute call with an ISO 42001 Lead Auditor maps your AI inventory to risk tiers and names the evidence each one needs. No obligation, and you keep the classification memo.
