EU AI Act

EU AI Act summary: the whole thing in plain English

The AI Act runs to more than a hundred articles and thirteen annexes. Almost none of it applies to an ordinary business. This summary covers the parts that do, and skips the parts written for machinery manufacturers.

Last reviewed: August 2026

What the Act is trying to do

Regulation (EU) 2024/1689 is a product-safety law applied to software. Rather than regulating AI as a technology, it regulates AI by use case: the same model can be unregulated in one setting and high risk in another. The obligations scale with the harm the use could cause to health, safety or fundamental rights.

The four risk tiers

  • Unacceptable risk — prohibited. Social scoring by public or private bodies, manipulative or exploitative techniques, emotion inference in workplaces and education, untargeted scraping of facial images, and most real-time remote biometric identification in public spaces.
  • High risk — permitted with strict conditions. Annex III lists the areas: biometrics, critical infrastructure, education, employment and worker management, access to essential public and private services including credit and insurance, law enforcement, migration, and justice.
  • Limited risk — transparency only. Users must be told they are dealing with an AI system; deepfakes and synthetic media must be labelled; AI-generated text published on matters of public interest must be disclosed.
  • Minimal risk — no specific obligations. This is where most everyday business software sits.

Provider duties vs deployer duties

The Act splits obligations between the organisation that builds or brands an AI system (the provider) and the organisation that uses it under its own authority (the deployer). Buyers of AI tools are usually deployers.

  • Providers of high-risk systems: risk management system, data governance, technical documentation, automatic logging, instructions for use, human-oversight design, accuracy and cybersecurity, conformity assessment, EU database registration, and post-market monitoring.
  • Deployers of high-risk systems: use the system per its instructions, assign competent human oversight, ensure input data is relevant, keep logs, inform affected workers and individuals, and cooperate with authorities. Public bodies and some private deployers also run a fundamental rights impact assessment.
  • Everyone: AI literacy. Organisations must ensure staff dealing with AI systems have a sufficient level of understanding.

Watch the role switch

Put your own name on someone else's AI system, or change its intended purpose, and you become the provider — inheriting the full high-risk obligation set. This is the single most expensive mistake a reseller or agency can make.

General-purpose AI models

Models like the ones behind mainstream chat assistants carry their own obligations: technical documentation, information for downstream providers, a copyright policy, and a public summary of training content. Models posing systemic risk carry additional evaluation, incident-reporting and cybersecurity duties. These fall on the model provider, not on you as a business user — but the documentation they publish is what you rely on to evidence your own compliance.

Penalties

  • Prohibited practices: up to €35 million or 7% of total worldwide annual turnover, whichever is higher.
  • Most other breaches: up to €15 million or 3% of turnover.
  • Supplying incorrect or misleading information to authorities: up to €7.5 million or 1% of turnover.
  • Caps are lower for SMEs and start-ups, where the lower of the two figures applies.

Timeline

  • 1 August 2024 — the Act entered into force.
  • 2 February 2025 — prohibitions and AI literacy obligations apply.
  • 2 August 2025 — general-purpose AI model obligations, governance and penalties apply.
  • 2 August 2026 — general application, including Annex III high-risk obligations and transparency duties.
  • 2 August 2027 — high-risk obligations for AI as a safety component of regulated products.

See where your own AI use actually stands

Register the AI tools your team uses and get a risk rating for each one, in plain English. Free, and it takes about ten minutes.

Not legal advice. This guide explains how the rules are generally understood and is here to help you get organised. It isn't a substitute for advice from a qualified solicitor or your own compliance team.