The AI Act, article by article.
One page per article: who it binds, what it requires, when it applies after Regulation (EU) 2026/1744 moved several dates, and the misunderstanding that most often causes trouble. Every page links the primary source and shows what regulators have published on that article recently.
36 entries · as of 2026-08-04
What may not be placed on the market at all, in force since February 2025.
- Art. 5 Article 5: Prohibited AI Practices Article 5 bans specific AI uses outright, regardless of risk classification elsewhere in the Act: manipulative or deceptive techniques that cause harm, exploitation of vulnerable groups, social scoring, certain biometric categorisation and untargeted facial-image scraping, workplace and education emotion recognition, and real-time remote biometric identification in public spaces (with narrow law-enforcement exceptions).
- Art. 99 Article 99: General Penalties Article 99 sets the penalty framework member states must implement for AI Act violations other than the GPAI-specific fines under Article 101: the highest tier applies to breaches of the Article 5 prohibitions, a middle tier applies to breaches of most other obligations (such as the high-risk provider and deployer duties), and a lower tier applies to supplying incorrect, incomplete, or misleading information to authorities or notified bodies..
Classification and the duties that follow, now applying from December 2027.
- Art. 6 Article 6: Classification of High-Risk AI Systems Article 6 sets out two routes into the high-risk category: Article 6(1) for AI embedded as a safety component in products already regulated under EU product-safety law (Annex I), and Article 6(2) for standalone AI used in the use cases listed in Annex III.
- Art. 8 Article 8: General Compliance for High-Risk Systems Article 8 is the chapeau provision for the high-risk chapter: it requires providers to comply with the full set of requirements in Articles 9 to 15, and ties that compliance to the system's stated intended purpose and to the current state of the art.
- Art. 9 Article 9: Risk Management System Article 9 requires providers of high-risk systems to run a continuous, iterative risk management process across the entire lifecycle of the system, identifying and mitigating known and reasonably foreseeable risks to health, safety, and fundamental rights.
- Art. 10 Article 10: Data and Data Governance Article 10 requires that training, validation, and testing data used for high-risk AI systems be subject to appropriate data governance practices, and be relevant, sufficiently representative, and to the best extent possible free of errors and complete for the intended purpose.
- Art. 11 Article 11: Technical Documentation Article 11 requires providers to draw up technical documentation before a high-risk system is placed on the market, following the minimum content set out in Annex IV, and to keep it up to date.
- Art. 12 Article 12: Record-Keeping and Automatic Logging Article 12 requires high-risk AI systems to technically allow for the automatic recording of events (logs) over the system's lifetime, at a level that ensures traceability of the system's functioning appropriate to its intended purpose.
- Art. 13 Article 13: Transparency to Deployers Article 13 requires high-risk systems to be designed so their operation is sufficiently transparent to deployers, and requires providers to supply instructions for use covering the system's intended purpose, level of accuracy, known risks, human oversight measures, and expected lifetime.
- Art. 14 Article 14: Human Oversight Article 14 requires high-risk systems to be designed to allow effective human oversight during use, through measures built into the system by the provider and/or measures the deployer can apply.
- Art. 15 Article 15: Accuracy, Robustness, Cybersecurity Article 15 requires high-risk systems to achieve an appropriate level of accuracy, robustness, and cybersecurity, and to perform consistently in these respects throughout their lifecycle.
- Art. 16 Article 16: Provider Obligations Bundle Article 16 is the consolidating provision listing everything a provider of a high-risk system must do: comply with Articles 9 to 15, have a quality management system, keep documentation and logs, carry out conformity assessment, affix CE marking, register the system, take corrective action if needed, and cooperate with authorities.
- Art. 17 Article 17: Quality Management System Article 17 requires providers of high-risk systems to put in place a documented quality management system covering strategy, design control, testing, data management, post-market monitoring, and incident reporting procedures.
- Art. 22 Article 22: Authorised Representative for High-Risk Systems Article 22 requires providers of high-risk AI systems established outside the EU to appoint, by written mandate, an authorised representative established in the EU before making the system available on the EU market.
- Art. 23 Article 23: Importer Obligations Article 23 requires importers to verify, before placing a high-risk system on the EU market, that the provider has carried out the required conformity assessment and that technical documentation, CE marking, and the EU declaration of conformity exist.
- Art. 24 Article 24: Distributor Obligations Article 24 requires distributors — anyone in the supply chain other than the provider or importer who makes a high-risk system available on the market — to verify before doing so that the system bears the required CE marking, is accompanied by the EU declaration of conformity, and that the provider and importer have met their respective obligations..
- Art. 25 Article 25: When a Deployer Becomes a Provider Article 25 sets out when another actor in the value chain — typically a deployer — is treated as the provider and takes on the full Article 8 to 22 obligation set: when it puts its own name or trademark on a high-risk system, when it makes a substantial modification to an already placed system, or when it changes the intended purpose of a system in a way that makes it high-risk..
- Art. 26 Article 26: Deployer Obligations Article 26 sets out what organisations using a high-risk AI system in the course of a professional activity must do: use it according to the instructions for use, assign competent human oversight, monitor its operation, retain logs, inform workers and affected people, and cooperate with market surveillance authorities.
- Art. 27 Article 27: Fundamental Rights Impact Assessment (FRIA) Article 27 requires certain deployers — public-sector bodies, private operators of essential public services, and deployers of specific Annex III systems such as creditworthiness assessment and life/health insurance risk pricing — to carry out a Fundamental Rights Impact Assessment before first using a high-risk system, and to notify the market surveillance authority.
- Art. 43 Article 43: Conformity Assessment Article 43 sets out which conformity assessment procedure a provider must follow before placing a high-risk system on the market: an internal control procedure under Annex VI for most Annex III use cases, or assessment involving a notified body under Annex VII for certain categories such as biometric identification, or where no harmonised standard exists and specific conditions apply..
- Art. 47 Article 47: EU Declaration of Conformity Article 47 requires providers to draw up a written, signed EU declaration of conformity for each high-risk system, stating that the requirements of Articles 8 to 15 have been met, and to keep it available to national authorities for ten years after the system is placed on the market.
- Art. 48 Article 48: CE Marking Article 48 requires providers to affix the CE marking to a high-risk system, or to its packaging or accompanying documentation, after the conformity assessment under Article 43 has been successfully completed.
- Art. 49 Article 49: Registration Article 49 requires providers of Annex III high-risk systems to register the system in the EU database referred to in Article 71 before placing it on the market or putting it into service.
- Art. 71 Article 71: EU Database Article 71 establishes the EU database into which Annex III high-risk systems, and Article 6(3) self-assessments concluding a system is not high-risk, must be registered under Article 49.
- Annex III Annex III: List of High-Risk Use Cases Annex III lists the use-case categories that make a standalone AI system high-risk under Article 6(2): biometrics, critical infrastructure, education and vocational training, employment and worker management, access to essential services, law enforcement, migration and border control, and administration of justice and democratic processes.
- Annex IV Annex IV: Technical Documentation Requirements Annex IV sets the minimum content structure for the technical documentation providers must draw up under Article 11: a general system description, design and development details, information on monitoring and control, risk management system details, and validation/testing information, kept current across the system's lifecycle..
Disclosure duties for chatbots, deepfakes and synthetic content.
Model-level obligations, in force since August 2025 and untouched by the Omnibus.
- Art. 51 Article 51: Systemic-Risk Classification of GPAI Models Article 51 defines when a general-purpose AI model is classified as posing systemic risk: either because it has high-impact capabilities evaluated against appropriate technical tools and benchmarks, with a rebuttable presumption triggered by cumulative training compute above 10^25 floating point operations, or because the Commission classifies it independently, including following a qualified alert from the scientific panel under the Annex XIII criteria..
- Art. 52 Article 52: Notification and Re-assessment Procedure Article 52 requires GPAI providers to notify the Commission without delay, and in any case within two weeks, once their model reaches or is foreseeable to reach the systemic-risk threshold, with the option to submit substantiated arguments against classification.
- Art. 53 Article 53: GPAI Provider Obligations Article 53 sets the baseline obligations for every provider of a general-purpose AI model: keep technical documentation per Annex XI, give downstream integrators information per Annex XII, run a copyright compliance policy, and publish a public training-content summary using the Commission's template.
- Art. 54 Article 54: GPAI Authorised Representative Article 54 requires non-EU providers of general-purpose AI models to appoint, by written mandate, an authorised representative established in the EU before placing the model on the market.
- Art. 55 Article 55: Systemic-Risk GPAI Obligations Article 55 requires providers of GPAI models classified as posing systemic risk to evaluate their models including documented adversarial testing, assess and mitigate systemic risks at Union level, track and report serious incidents to the AI Office, and maintain adequate cybersecurity for the model and its infrastructure.
- Art. 56 Article 56: GPAI Codes of Practice Article 56 provides for Codes of Practice, developed with GPAI providers, civil society, and other stakeholders under the AI Office's coordination, as a recognised way for providers to demonstrate compliance with Articles 53 and 55 until harmonised standards are published.
- Art. 101 Article 101: GPAI Fines Article 101 lets the Commission fine GPAI providers up to 3% of worldwide annual turnover in the preceding financial year, or EUR 15 million, whichever is higher, for intentional or negligent infringement of the Regulation, for failing to respond or giving false or misleading information under Article 91, for non-compliance with a corrective measure under Article 93, or for refusing model access for evaluation under Article 92..
- Annex XI Annex XI: GPAI Technical Documentation Annex XI sets the minimum content for the technical documentation GPAI providers must draw up and keep under Article 53(1)(a): information on the model's development process, training and testing process and results, and, where relevant, information about the energy consumption of training.
Registration, authorities, penalties and the timeline provisions.
Ask it instead of reading it.
The same record answers queries from an agent: which obligations apply to a role and risk class, what changed since a date, what a given article requires. Webhook, REST API and MCP server, free during the beta.
Get free access