AI Act Digest

The EU AI Act for study, in two layers. Part 1 is Regulation (EU) 2024/1689 itself as amended by Regulation (EU) 2026/1744, the Digital Omnibus on AI in force since 27 July 2026: all 119 articles (the 113 of the original text plus the six the Omnibus inserted) and 14 annexes, grouped by chapter, each with a takeaway written from the consolidated text stating what it establishes, who it binds and what to do, its date of application, the recitals that explain it, and a flag on the 43 provisions the Omnibus changed. Part 2 is the corpus around the Act as of 19 September 2026: 57 documents, from the Commission's guidelines, codes of practice, templates and Q&As through the standardisation programme, EDPB and EDPS opinions including Opinion 28/2024 on AI models, national implementing laws and the reference tools, each with a takeaway and the articles it interprets.

Three limits, stated up front. A takeaway is a reading aid and the text governs; every entry links to the source. Application dates are the ones the consolidated text carries under Article 113 after the Omnibus; the high-risk chapter applies from 2 December 2027 for Annex III systems and 2 August 2028 for Annex I systems, not the 2 August 2026 date the original Act set. Guidance marked draft or consultation is not final and may change. None of this is legal advice.

Filters, search and the checker run in your browser. Nothing you type is sent anywhere.

High-level summary The Act in ten short sections; open any one

What the Act is

Risk tiers, one amending regulation

Regulation (EU) 2024/1689 is a product-safety style law for AI. It sorts AI systems by the risk they pose and attaches obligations to that tier: a short list of practices is banned outright, high-risk systems carry the full set of design, documentation and oversight requirements, a handful of uses carry transparency duties only, and everything else is left alone apart from a duty to support AI literacy. General-purpose AI models are a separate layer with their own obligations on the model provider. Regulation (EU) 2026/1744, the Digital Omnibus on AI, amended it with effect from 27 July 2026, mainly by moving the high-risk dates, adding two prohibitions, softening the literacy duty and giving the AI Office direct enforcement powers.

Who it binds

Providers, deployers, the supply chain, the exclusions

The Act reaches anyone who places an AI system or a general-purpose AI model on the Union market, wherever they are established, anyone who deploys a system inside the Union, and third-country operators whose output is used in the Union (Article 2). The roles that matter are the provider, who develops a system or model and puts it on the market under its own name, the deployer, who uses a system under its own authority in a professional setting, and the importer, distributor, product manufacturer and authorised representative in the supply chain (Article 3). Most obligations sit with providers of high-risk systems; deployers carry a shorter list.

  • Out of scope: military, defence and national security uses; scientific research and development; testing before a system is placed on the market; purely personal, non-professional use (Article 2).
  • Free and open-source systems are outside the Act unless they are high-risk, prohibited, or caught by the Article 50 transparency duties.
  • Providers and deployers must support AI literacy among staff and other persons operating systems on their behalf, since 2 February 2025; after the Omnibus no particular level of literacy has to be guaranteed for any individual (Article 4).

Prohibited practices

Ten banned uses, fines up to 7 % of turnover

Article 5 bans practices whose risk is judged unacceptable. Since 2 February 2025: manipulative or deceptive techniques that distort behaviour and cause significant harm; exploiting age, disability or social or economic vulnerability; social scoring by public or private actors that leads to detrimental treatment; predicting criminal offending from profiling or personality traits alone; untargeted scraping of facial images from the internet or CCTV to build recognition databases; emotion recognition in workplaces and education except for medical or safety reasons; biometric categorisation that infers race, political opinions, trade union membership, religion, sex life or sexual orientation; and real-time remote biometric identification in public spaces for law enforcement, allowed only for victim searches, imminent threats or serious offences with prior authorisation and a fundamental rights impact assessment. From 2 December 2026 the Omnibus adds two more: AI systems that generate or manipulate non-consensual intimate imagery, and systems that generate child sexual abuse material. Fines reach EUR 35 000 000 or 7 % of worldwide annual turnover (Article 99).

High-risk AI systems

Two routes in, the requirements, the dates

There are two routes into the high-risk tier (Article 6). The first is product law: an AI system that is a safety component of, or is itself, a product covered by the Union harmonisation legislation in Annex I and subject to third-party conformity assessment (machinery, toys, lifts, medical devices, vehicles, aircraft and so on). The second is the list of stand-alone use cases in Annex III: biometrics, critical infrastructure, education and vocational training, employment and worker management, access to essential public and private services including credit scoring and life and health insurance, law enforcement, migration and border control, and the administration of justice and elections. An Annex III system escapes the tier if it only performs a narrow procedural task, improves the result of a completed human activity, detects deviations from earlier decisions or does preparatory work, but profiling of natural persons is always high-risk, and the provider must document the assessment and register the system anyway.

  • Requirements on the system (Article 8 to Article 15): a lifecycle risk management system, data governance for training, validation and testing sets, technical documentation to Annex IV, automatic logging, instructions for use, effective human oversight, and accuracy, robustness and cybersecurity.
  • Provider duties (Article 16 to Article 22): a quality management system, ten years of documentation, log retention, corrective action, cooperation with authorities, and an authorised representative for non-EU providers. Before placing on the market: conformity assessment (Article 43), EU declaration of conformity (Article 47), CE marking (Article 48) and registration in the EU database (Article 49, Article 71). Afterwards: post-market monitoring (Article 72) and serious incident reporting (Article 73).
  • Deployer duties (Article 26): use the system as instructed, assign competent human oversight, keep input data relevant, monitor and report, keep logs for at least six months, tell workers' representatives before use and tell people subject to decisions. Public bodies, providers of public services and users of credit scoring and life and health insurance systems complete a fundamental rights impact assessment before first use (Article 27). Affected persons can demand an explanation of decisions (Article 86).
  • Supply chain (Article 23 to Article 25): importers and distributors verify conformity before they trade; a distributor, importer or deployer becomes the provider if it rebrands or substantially modifies a system, or changes its intended purpose so that it becomes high-risk.
  • Dates after the Omnibus: Annex III systems from 2 December 2027, Annex I systems from 2 August 2028. Systems already on the market are caught only if their design changes significantly, except systems used by public authorities, which must comply by 2 August 2030 (Article 111).

Transparency duties

Article 50: chatbots, synthetic content, deep fakes

Article 50 covers four situations regardless of risk tier. Providers must design systems that interact directly with people so that people know they are dealing with AI, and must mark synthetic audio, image, video and text output in a machine-readable, detectable way. Deployers must tell people when they are exposed to emotion recognition or biometric categorisation, and must disclose deep fakes and AI-generated text published on matters of public interest, with exceptions for artistic works and text under editorial responsibility. These duties apply from 2 August 2026; providers of content generators already on the market before that date have until 2 December 2026 to comply with the marking duty (Article 111). A code of practice on detecting and labelling AI-generated content, and the Commission's guidelines on Article 50, were published in July 2026.

General-purpose AI models

Documentation, copyright, the 10^25 FLOP line

A general-purpose AI model displays significant generality and can perform a wide range of tasks; it is regulated at model level, separately from the systems built on it. Every provider must keep technical documentation to Annex XI, give downstream system providers the Annex XII information they need, adopt a copyright policy that respects rights reservations under the Copyright Directive, and publish a summary of training content on the AI Office template (Article 53). Free and open-source models with public weights are exempt from the documentation duties unless they carry systemic risk. A model is presumed to have systemic risk once cumulative training compute exceeds 10^25 floating point operations, or the Commission designates it (Article 51); its provider must then also run standardised evaluations including adversarial testing, assess and mitigate systemic risks, report serious incidents to the AI Office and secure the model and its infrastructure (Article 55). The General-Purpose AI Code of Practice of 10 July 2025 is the recognised route to compliance (Article 56). Obligations applied from 2 August 2025; models already on the market then have until 2 August 2027 (Article 111). The Commission may fine model providers up to EUR 15 000 000 or 3 % of worldwide turnover (Article 101), with fining possible from 2 August 2026.

Governance and enforcement

AI Office, Board, national authorities, complaints

At Union level the AI Office inside the Commission supervises general-purpose AI models and, after the Omnibus, has direct powers to investigate, request information, inspect premises and impose fines and periodic penalty payments on the operators assigned to it (Article 64, Article 75a to Article 75d). The European Artificial Intelligence Board coordinates Member States (Article 65), an advisory forum and a scientific panel of independent experts support both (Article 67, Article 68), and the panel can raise qualified alerts about systemic-risk models (Article 90). Each Member State designates a notifying authority and a market surveillance authority, with one single point of contact (Article 70); data protection authorities supervise the law enforcement, migration and justice use cases. Anyone may complain to a market surveillance authority (Article 85), and whistleblowers are protected (Article 87). Regulatory sandboxes, at least one per Member State since 2 August 2026, and real-world testing give providers a supervised route to market (Article 57 to Article 61).

Penalties

Three tiers, lower caps for SMEs and small mid-caps
  • Prohibited practices: up to EUR 35 000 000 or 7 % of worldwide annual turnover, whichever is higher.
  • Other obligations of providers, deployers, importers, distributors, notified bodies and the Article 50 duties: up to EUR 15 000 000 or 3 %.
  • Incorrect, incomplete or misleading information to authorities: up to EUR 7 500 000 or 1 %.
  • For SMEs and small mid-caps the lower of the two amounts applies (Article 99). Union institutions face separate fines from the European Data Protection Supervisor (Article 100).

Timeline after the Omnibus

From 1 August 2024 to 31 December 2030
  • 1 August 2024: entry into force.
  • 2 February 2025: general provisions, AI literacy and the prohibitions (Chapters I and II).
  • 2 August 2025: notified bodies, general-purpose AI models, governance, penalties and confidentiality (Chapter III Section 4, Chapters V, VII and XII, Article 78), except the GPAI fining power.
  • 27 July 2026: Regulation (EU) 2026/1744 in force; the inserted Articles 4a, 60a and 75a to 75d, and the sectoral amendments in Articles 102 to 110.
  • 2 August 2026: everything else, including the Article 50 transparency duties, sandboxes, the GPAI fining power and the AI Office's enforcement powers.
  • 2 December 2026: the two new prohibitions; deadline for existing content generators to mark synthetic output.
  • 2 August 2027: deadline for general-purpose AI models already on the market.
  • 2 December 2027: high-risk obligations for Annex III systems.
  • 2 August 2028: high-risk obligations for Annex I product-related systems.
  • 2 August 2030: high-risk systems used by public authorities; 31 December 2030: components of the Annex X large-scale IT systems (Article 113, Article 111).

What the Omnibus changed

Eight changes worth knowing
  • High-risk dates moved from 2 August 2026 to 2 December 2027 (Annex III) and 2 August 2028 (Annex I), with grandfathering keyed to the new dates (Article 113, Article 111).
  • Two new prohibitions on non-consensual intimate imagery and child sexual abuse material from 2 December 2026 (Article 5).
  • AI literacy became a duty to support literacy, without guaranteeing any individual level (Article 4); a new Article 4a allows processing of special categories of personal data for bias detection and correction under strict conditions.
  • Systems that only serve non-safety aspects such as user assistance or convenience are not safety components under Article 6(1) unless failure endangers health and safety (Article 6).
  • Article 50 marking duty: providers of generators already on the market get until 2 December 2026; the Commission can approve or replace a code of practice on labelling by implementing act (Article 50, Article 111).
  • The AI Office gained supervisory and enforcement powers, commitments, fines and periodic penalty payments over the operators in Article 75(1), plus a Union-level sandbox (Article 75a to Article 75d, Article 57).
  • Small mid-caps (SMCs) join SMEs in the simplified quality management, fee, guidance and fine-cap provisions (Article 3, Article 17, Article 62, Article 99).
  • A new Article 60a covers real-world testing of Annex I Section B products; a new Annex XIV lists the codes and categories notified bodies are designated for; the Machinery Regulation (EU) 2023/1230 replaces the Machinery Directive in Annex I.
Which obligations apply? A checker Ten questions at most; open to start

Answer a few questions about one AI system or model and get the tier it falls in, the articles that apply to your role, and the dates after the Omnibus. Runs in your browser; nothing is stored or sent. A reading aid, not legal advice: the answers point you to the provisions to read, they do not decide the case.

Part 2, guidance and implementation. Jump to a group:

Structure of the Act

Annexes 14
Supplementary lists, procedures and templates
Recitals 180
Context and reasoning behind the Act. Click a number to show the provisions that cite it; 168 of the 180 are cited in this digest.

Part 1: the Regulation, article by article

Chapter I: General Provisions5 provisions

Article 1: Subject Matter

applies 2 February 2025Everyonescope

Article 1 states the purpose of the Regulation: to improve the functioning of the internal market, promote human-centric and trustworthy AI and protect health, safety and fundamental rights while supporting innovation (paragraph 1). Paragraph 2 lists what the Regulation contains: harmonised rules for placing AI systems and general-purpose AI models on the market, prohibitions of certain practices, requirements for high-risk systems and their operators, transparency rules, rules on general-purpose AI models, market surveillance and enforcement, and innovation support for SMEs, start-ups and small mid-caps. It binds everyone in scope and is the reference point for reading every later obligation.

Recitals 1, 2, 3, 6, 7, 8

Article 2: Scope

applies 2 February 2025amended by 2026/1744Everyonescope

Article 2 fixes who is caught: providers placing AI systems or general-purpose AI models on the Union market wherever established, deployers in the Union, third-country operators whose output is used in the Union, importers, distributors, product manufacturers, authorised representatives and affected persons (paragraph 1). Paragraphs 3 to 12 exclude military, defence and national security uses, scientific research, pre-market testing, purely personal use and free and open-source systems unless high-risk or caught by Articles 5 or 50. Paragraph 2 confines Annex I Section B products to Article 6(1), Article 60a and Articles 102 to 112; paragraph 13 lets the Commission limit Articles 9 to 15 by 2 August 2027.

Paragraph 2 was rewritten so that only Article 6(1), Article 60a and Articles 102 to 112 apply to Annex I Section B products, with Articles 57 to 59 applying only where integrated into that sectoral legislation, and paragraph 7 now cross-refers to the new Article 4a.

Recitals 9, 21, 22, 23, 24, 25, 166

Article 3: Definitions

applies 2 February 2025amended by 2026/1744Everyonescopeother

Article 3 supplies the 68 definitions on which every later obligation depends. An AI system is a machine-based system with varying levels of autonomy that infers from input how to generate outputs such as predictions, content, recommendations or decisions (point 1); a provider develops a system or model and places it on the market under its own name (point 3); a deployer uses a system under its authority outside personal activity (point 4). Points 63 and 65 define general-purpose AI models and systemic risk, and point 49 defines a serious incident as death, serious harm to health, critical infrastructure disruption, a fundamental rights infringement or serious harm to property.

Point 14a now refers to Recommendation 2003/361/EC for SMEs and new point 14b defines a small mid-cap enterprise (SMC) by reference to Recommendation (EU) 2025/1099.

Recitals 12, 13, 14, 15, 16, 17, 18, 19, 97, 98, 99, 100, 110, 128

Article 4: AI Literacy

applies 2 February 2025amended by 2026/1744ProvidersDeployersCommissionliteracy

Article 4 obliges providers and deployers of AI systems to take measures that support AI literacy among their staff and other persons operating the systems on their behalf, taking account of technical knowledge, experience, education, training, the context of use and the persons affected (paragraph 1). No specific level of literacy has to be guaranteed for any individual. Under paragraph 2 the Commission and Member States support providers and deployers, particularly SMEs, with practical examples published on the Article 62(3) platform, and under paragraph 3 the Board adopts recommendations on common objectives. Document role-based training now; the obligation has applied since 2 February 2025.

Paragraph 1 was softened to a duty to support literacy without guaranteeing any individual level, and new paragraphs 2 and 3 add Commission, Member State and Board support duties.

Recitals 20

Article 4a: Processing of special categories of personal data for bias detection and correction

applies 27 July 2026amended by 2026/1744ProvidersDeployersdataprovider dutiesdeployer duties

Article 4a lets providers of high-risk AI systems process special categories of personal data, for bias detection and correction, under six cumulative conditions (paragraph 1, points (a) to (f)): other data including synthetic or anonymised data cannot do the job, technical limits on re-use and state-of-the-art security measures apply, access is strictly controlled and documented, the data is not passed to other parties, it is deleted once the bias is corrected or the retention period ends, and the processing record explains the necessity. Paragraph 2 extends the permission, under the same safeguards, to providers and deployers of other AI systems and deployers of high-risk systems, where strictly necessary to address biases affecting health and safety, fundamental rights or prohibited discrimination. It imposes no duty to detect bias.

Inserted by Regulation (EU) 2026/1744: it moves the special category data permission out of Article 10(5) into a general provision and extends it to providers and deployers of non-high-risk systems and to deployers of high-risk systems.

Chapter II: Prohibited AI Practices1 provision

Article 5: Prohibited AI Practices

applies 2 February 2025 (points (ba) and (bb) from 2 December 2026)amended by 2026/1744Everyoneprohibitions

Article 5 prohibits eight AI practices: manipulative techniques, exploitation of vulnerabilities, social scoring, criminal risk prediction based solely on profiling, untargeted scraping of facial images, emotion recognition in workplaces and education except for medical or safety reasons, biometric categorisation inferring protected characteristics, and real-time remote biometric identification in public spaces for law enforcement (paragraph 1). Point (h) allows real-time identification only for victim searches, imminent threats or Annex II offences carrying at least four years' custody, with prior authorisation and a fundamental rights impact assessment (paragraphs 2 to 4). New points (ba) and (bb) ban generating non-consensual intimate imagery and child sexual abuse material from 2 December 2026.

New points 1(ba) and 1(bb) and paragraphs 1a and 1b add prohibitions on AI systems generating or manipulating non-consensual intimate imagery and child sexual abuse material, applying from 2 December 2026.

Recitals 3, 28, 29, 30, 31, 32, 33, 34, 35, 38, 39, 40, 41, 42, 43, 44, 45

Chapter III: High-Risk AI Systems44 provisions

Article 6: Classification Rules for High-Risk AI Systems

applies 2 December 2027 (Annex III) or 2 August 2028 (Annex I)amended by 2026/1744ProvidersCommissionhigh risk classification

Article 6 sets the two routes to high-risk status: safety components of, or products under, Annex I harmonisation legislation that require third-party conformity assessment (paragraph 1), and the use cases in Annex III (paragraph 2). Paragraph 3 exempts Annex III systems that perform a narrow procedural task, improve a completed human activity, detect decision-making deviations or carry out preparatory assessments, but profiling of natural persons always stays high-risk. Providers relying on paragraph 3 must document the assessment before placing on the market and register under Article 49(2) (paragraph 4). New paragraphs 1a to 1c exclude systems limited to non-safety aspects such as user assistance unless failure endangers health and safety.

New paragraphs 1a, 1b and 1c state that systems used only for non-safety aspects such as user assistance, performance optimisation, service efficiency, automation, convenience or quality control are not safety components unless their failure endangers health and safety, and that products assessed solely for non-safety risks such as spectrum use do not meet paragraph 1.

Recitals 46, 47, 48, 50, 51, 52, 53, 54, 55, 56, 57, 58, 59, 60, 61, 62, 63

Article 7: Amendments to Annex III

applies 2 December 2027 (Annex III) or 2 August 2028 (Annex I)CommissionProvidershigh risk classificationgovernance

Article 7 empowers the Commission to adopt delegated acts under Article 97 adding or modifying Annex III use cases where a system falls within an existing Annex III area and poses a risk to health, safety or fundamental rights equivalent to or greater than the listed cases (paragraph 1). Paragraph 2 lists the criteria: intended purpose, extent of use, nature of data, autonomy and human override, documented harm, magnitude and reversibility of impact, benefits and existing remedies. Paragraph 3 allows removal of a use case that no longer poses a significant risk. Providers should monitor delegated acts because Annex III can change without a new regulation.

Article 8: Compliance with the Requirements

applies 2 December 2027 (Annex III) or 2 August 2028 (Annex I)Providersprovider dutiesconformity

Article 8 requires high-risk AI systems to meet the Section 2 requirements of Articles 9 to 15, read in the light of the intended purpose stated by the provider and the generally acknowledged state of the art, with the Article 9 risk management system used to verify compliance (paragraph 1). Where a product contains an AI system covered by both the Regulation and Annex I Section A harmonisation legislation, providers are responsible for full compliance with both sets of rules and may integrate the testing, reporting, information and documentation into what the sectoral legislation already requires (paragraph 2). Providers should build one integrated compliance file rather than parallel ones.

Recitals 46, 64

Article 9: Risk Management System

applies 2 December 2027 (Annex III) or 2 August 2028 (Annex I)Providersprovider duties

Article 9 obliges providers to establish, implement, document and maintain a risk management system for each high-risk AI system as a continuous iterative process across the whole lifecycle (paragraphs 1 and 2). The steps are identifying known and reasonably foreseeable risks to health, safety and fundamental rights, estimating risks under intended use and foreseeable misuse, evaluating Article 72 post-market monitoring data and adopting targeted measures so that residual risk is acceptable (paragraphs 2 to 5). Systems must be tested against predefined metrics and probabilistic thresholds before placing on the market, including Article 60 real-world testing where appropriate (paragraphs 6 to 8). Paragraph 9 protects persons under 18 and vulnerable groups.

Recitals 65

Article 10: Data and Data Governance

applies 2 December 2027 (Annex III) or 2 August 2028 (Annex I)amended by 2026/1744Providersdataprovider duties

Article 10 requires high-risk AI systems trained with data to use training, validation and testing datasets that meet the quality criteria in paragraphs 2 to 4 and Article 4a(1) (paragraph 1). Governance practices must cover design choices, data origin and collection, preparation and labelling, assumptions, availability and suitability, examination for bias affecting health, safety, fundamental rights or discrimination, bias mitigation and data gaps (paragraph 2). Datasets must be relevant, sufficiently representative, as error-free and complete as possible and reflect the geographical, contextual, behavioural and functional setting of use (paragraphs 3 and 4); for systems not trained on data only testing datasets are caught (paragraph 6).

Paragraph 5 on processing special categories of personal data for bias detection was deleted and moved to the new Article 4a, which paragraphs 1 and 6 now cross-refer to.

Recitals 66, 67, 68, 69, 70

Article 11: Technical Documentation

applies 2 December 2027 (Annex III) or 2 August 2028 (Annex I)amended by 2026/1744ProvidersNotified bodiesprovider dutiesconformity

Article 11 requires providers to draw up technical documentation before a high-risk AI system is placed on the market or put into service, keep it up to date and include at least the elements in Annex IV so that authorities and notified bodies can assess compliance (paragraph 1). SMEs, start-ups and small mid-caps may supply the elements in a simplified manner using the Commission's simplified form, which notified bodies must accept. Where the system relates to an Annex I Section A product, a single set of documentation covers both regimes (paragraph 2), and the Commission may amend Annex IV by delegated act (paragraph 3).

Paragraph 1 was amended so that SMEs, start-ups and small mid-caps may provide the documentation in a simplified manner using a Commission simplified form that notified bodies must accept.

Recitals 66, 71

Article 12: Record-Keeping

applies 2 December 2027 (Annex III) or 2 August 2028 (Annex I)Providersprovider dutiesoversight

Article 12 requires high-risk AI systems to technically allow automatic recording of events (logs) over their lifetime (paragraph 1). Logging must give traceability appropriate to the intended purpose so that Article 79(1) risks and substantial modifications can be identified, Article 72 post-market monitoring is supported and Article 26(5) deployer monitoring is possible (paragraph 2). For remote biometric identification systems under Annex III point 1(a), logs must at minimum record the start and end of each use, the reference database checked, the input data that produced a match and the persons who verified the result under Article 14(5) (paragraph 3). Providers design the logging; providers and deployers keep the logs.

Recitals 66, 71

Article 13: Transparency and Provision of Information to Deployers

applies 2 December 2027 (Annex III) or 2 August 2028 (Annex I)ProvidersDeployersprovider dutiestransparency

Article 13 requires high-risk AI systems to be designed so that their operation is sufficiently transparent for deployers to interpret and use the output appropriately (paragraph 1), and to ship with instructions for use that are concise, complete, correct and clear (paragraph 2). Paragraph 3 lists the mandatory content: provider and authorised representative identity, intended purpose, accuracy, robustness and cybersecurity levels, known risks and foreseeable misuse, performance for specific groups, input data specifications, predetermined changes, the human oversight measures under Article 14, computational and hardware needs, expected lifetime and maintenance, and the logging mechanisms under Article 12. Providers write these instructions; deployers rely on them for Articles 26 and 27.

Recitals 66, 72

Article 14: Human Oversight

applies 2 December 2027 (Annex III) or 2 August 2028 (Annex I)ProvidersDeployersoversightprovider duties

Article 14 requires high-risk AI systems to be designed with human-machine interface tools so that natural persons can effectively oversee them during use, to prevent or minimise risks to health, safety and fundamental rights (paragraphs 1 and 2). Measures must be proportionate to the risks and level of autonomy and are either built in by the provider or specified for the deployer (paragraph 3). Overseers must be able to understand capacities and limitations, resist automation bias, interpret output correctly, decide not to use the system, override it or halt it (paragraph 4). Remote biometric identification under Annex III point 1(a) needs separate verification by at least two persons (paragraph 5).

Recitals 66, 73

Article 15: Accuracy, Robustness and Cybersecurity

applies 2 December 2027 (Annex III) or 2 August 2028 (Annex I)ProvidersCommissionprovider dutiesstandards

Article 15 requires high-risk AI systems to achieve an appropriate level of accuracy, robustness and cybersecurity and to perform consistently throughout their lifecycle (paragraph 1). The Commission encourages benchmarks and measurement methodologies with stakeholders and metrology bodies (paragraph 2), and providers must declare accuracy levels and metrics in the instructions for use (paragraph 3). Robustness against errors, faults and inconsistencies may rely on redundancy, backup or fail-safe plans, and continuously learning systems must control biased feedback loops (paragraph 4). Cybersecurity measures must address data poisoning, model poisoning, adversarial examples, confidentiality attacks and model flaws (paragraph 5), so providers should map these threats into the Article 9 risk register.

Recitals 66, 74, 75, 76, 77, 78

Article 16: Obligations of Providers of High-Risk AI Systems

applies 2 December 2027 (Annex III) or 2 August 2028 (Annex I)Providersprovider dutiesconformity

Article 16 is the provider checklist for high-risk AI systems. Providers must ensure compliance with Section 2, mark the system or its packaging with their name and contact address, run an Article 17 quality management system, keep the Article 18 documentation and Article 19 logs, complete the Article 43 conformity assessment before placing on the market, draw up the Article 47 EU declaration of conformity, affix the CE marking under Article 48, register under Article 49(1), take corrective action under Article 20, demonstrate conformity on reasoned request and meet the accessibility requirements of Directives (EU) 2016/2102 and (EU) 2019/882 (points (a) to (l)).

Recitals 79, 80, 81, 145

Article 17: Quality Management System

applies 2 December 2027 (Annex III) or 2 August 2028 (Annex I)amended by 2026/1744Providersprovider duties

Article 17 requires providers of high-risk AI systems to run a documented quality management system with written policies, procedures and instructions covering thirteen areas (paragraph 1): regulatory compliance strategy, design and development controls, examination and testing, technical specifications and standards, data management, the Article 9 risk management system, Article 72 post-market monitoring, Article 73 serious incident reporting, communication with authorities and notified bodies, record-keeping, resource management and an accountability framework. Implementation is proportionate to the provider's size, including SMEs, start-ups and small mid-caps, without lowering protection (paragraph 2). Sectoral quality systems may be integrated (paragraph 3), and financial institutions satisfy most points through internal governance rules (paragraph 4).

Paragraph 2 now names small mid-caps (SMCs) alongside SMEs and start-ups among the organisations entitled to proportionate implementation.

Recitals 81

Article 18: Documentation Keeping

applies 2 December 2027 (Annex III) or 2 August 2028 (Annex I)Providersprovider duties

Article 18 obliges providers to keep, at the disposal of national competent authorities for 10 years after a high-risk AI system is placed on the market or put into service, the Article 11 technical documentation, the Article 17 quality management documentation, changes approved by notified bodies, notified body decisions and documents, and the Article 47 EU declaration of conformity (paragraph 1). Member States set the rules for the documentation when a provider or its authorised representative goes bankrupt or ceases activity before the 10 years end (paragraph 2), and financial institutions keep it under their financial services rules (paragraph 3). Set retention schedules to the 10-year clock from release.

Recitals 81

Article 19: Automatically Generated Logs

applies 2 December 2027 (Annex III) or 2 August 2028 (Annex I)Providersprovider dutiesoversight

Article 19 requires providers of high-risk AI systems to keep the logs their systems generate automatically under Article 12, to the extent the logs are under their control, for a period appropriate to the intended purpose and at least six months unless Union or national law, in particular data protection law, provides otherwise (paragraph 1). Financial institutions keep the logs as part of the documentation required by their financial services rules (paragraph 2). Providers should decide at design time which logs they control, for example in hosted deployments, and set retention accordingly; the matching deployer duty is in Article 26(6).

Recitals 81

Article 20: Corrective Actions and Duty of Information

applies 2 December 2027 (Annex III) or 2 August 2028 (Annex I)Providersprovider dutiesincidents

Article 20 requires providers who consider or have reason to consider that a high-risk AI system they have placed on the market is not in conformity to immediately bring it into conformity, withdraw it, disable it or recall it, and to inform the distributors, deployers, authorised representative and importers concerned (paragraph 1). Where the system presents an Article 79(1) risk and the provider becomes aware of it, the provider must immediately investigate the causes with the reporting deployer and inform the market surveillance authorities and, where applicable, the certifying notified body, describing the non-compliance and the corrective action (paragraph 2). Providers need a recall and notification procedure before release.

Recitals 81

Article 21: Cooperation with Competent Authorities

applies 2 December 2027 (Annex III) or 2 August 2028 (Annex I)ProvidersAuthoritiesprovider dutiesenforcement

Article 21 requires providers of high-risk AI systems, on reasoned request from a competent authority, to supply all information and documentation necessary to demonstrate conformity with Section 2 in an official Union language that the requesting Member State can readily understand (paragraph 1) and to give access to the automatically generated logs referred to in Article 12(1) to the extent those logs are under their control (paragraph 2). Information obtained is protected by the confidentiality obligations in Article 78 (paragraph 3). Providers should keep the technical file in a form that can be handed over on request and know which languages their markets require.

Recitals 81

Article 22: Authorised Representatives of Providers of High-Risk AI Systems

applies 2 December 2027 (Annex III) or 2 August 2028 (Annex I)Providersprovider dutiesregistration

Article 22 requires providers established outside the Union to appoint, by written mandate and before placing a high-risk AI system on the Union market, an authorised representative established in the Union (paragraph 1). The representative verifies that the EU declaration of conformity and technical documentation exist and the conformity assessment was carried out, keeps the provider's contact details and documentation copies for 10 years after placing on the market, supplies information to authorities on reasoned request, cooperates on risk mitigation and complies with Article 49(1) registration (paragraph 3). The representative must terminate the mandate and inform the market surveillance authority if the provider breaches the Regulation (paragraph 4).

Recitals 82, 83

Article 23: Obligations of Importers

applies 2 December 2027 (Annex III) or 2 August 2028 (Annex I)Importersprovider dutiesconformity

Article 23 requires importers, before placing a high-risk AI system on the market, to verify that the provider has carried out the Article 43 conformity assessment, drawn up the Annex IV technical documentation, affixed the CE marking, supplied the EU declaration of conformity and instructions for use and appointed an authorised representative under Article 22(1) (paragraph 1). An importer with reason to believe the system is non-conforming must not place it on the market and must report any Article 79(1) risk (paragraph 2). Importers add their own name and address, keep the certificate, instructions and declaration for 10 years and cooperate with authorities (paragraphs 3 to 7).

Recitals 83

Article 24: Obligations of Distributors

applies 2 December 2027 (Annex III) or 2 August 2028 (Annex I)Distributorsprovider dutiesconformity

Article 24 requires distributors, before making a high-risk AI system available, to verify that it bears the CE marking, is accompanied by the EU declaration of conformity and instructions for use, and that the provider and importer have met their marking duties under Article 16(b) and (c) and Article 23(3) (paragraph 1). A distributor with reason to believe the system does not meet Section 2 must not make it available and must report any Article 79(1) risk (paragraph 2). Distributors protect the system in storage and transport, take or secure corrective action, withdrawal or recall on discovering non-conformity, and cooperate with authorities (paragraphs 3 to 6).

Recitals 83

Article 25: Responsibilities Along the AI Value Chain

applies 2 December 2027 (Annex III) or 2 August 2028 (Annex I)amended by 2026/1744ProvidersDeployersDistributorsprovider dutieshigh risk classification

Article 25 makes any distributor, importer, deployer or other third party the provider of a high-risk AI system, with all Article 16 duties, where it puts its name on the system, makes a substantial modification that keeps or renders it high-risk, or changes the intended purpose so that the system becomes high-risk (paragraph 1). The initial provider then ceases to be provider but must supply technical documentation, known limitations and failure modes and targeted technical access, unless it clearly specified that the system was not to become high-risk (paragraph 2). Annex I Section A product manufacturers are the provider (paragraph 3); component suppliers must agree assistance in writing (paragraph 4).

Paragraph 2 now spells out the initial provider's cooperation duties (technical documentation, known limitations and failure modes, targeted technical access) and paragraph 4 lets the AI Office develop and recommend voluntary model contract terms for component suppliers.

Recitals 83, 84, 85, 86, 87, 88, 89, 90

Article 26: Obligations of Deployers of High-Risk AI Systems

applies 2 December 2027 (Annex III) or 2 August 2028 (Annex I)Deployersdeployer dutiesoversight

Article 26 is the deployer checklist for high-risk AI systems. Deployers must follow the instructions for use (paragraph 1), assign human oversight to persons with competence, training and authority (paragraph 2), ensure input data under their control is relevant and representative (paragraph 4), monitor operation, report risks and serious incidents to the provider and market surveillance authority and suspend use (paragraph 5), and keep logs for at least six months (paragraph 6). Employers inform workers' representatives before use (paragraph 7), public authorities register under Article 49 (paragraph 8), and deployers inform persons subject to decisions (paragraph 11). Post-remote biometric identification in criminal investigations needs authorisation within 48 hours (paragraph 10).

Recitals 91, 92, 93, 94, 95

Article 27: Fundamental Rights Impact Assessment for High-Risk AI Systems

applies 2 December 2027 (Annex III) or 2 August 2028 (Annex I)amended by 2026/1744Deployersfriadeployer duties

Article 27 requires deployers that are bodies governed by public law, private operators providing public services, and deployers of the credit scoring and life and health insurance systems in Annex III point 5(b) and (c) to complete a fundamental rights impact assessment before first use (paragraph 1). The assessment covers the deployer's processes and intended use, the period and frequency of use, the persons affected, the risks of harm, the human oversight measures and the mitigation and complaint arrangements. It is done once, updated when elements change (paragraph 2), notified to the market surveillance authority (paragraph 3) and may build on a GDPR Article 35 assessment (paragraph 4).

Paragraph 5 was amended so that the AI Office develops the questionnaire template including through an automated tool to simplify compliance.

Recitals 4, 5, 26, 93, 96

Article 28: Notifying Authorities

applies 2 August 2025amended by 2026/1744AuthoritiesNotified bodiesconformitygovernance

Article 28 requires each Member State to designate or establish at least one notifying authority responsible for assessing, designating, notifying and monitoring conformity assessment bodies (paragraph 1), which may be its national accreditation body under Regulation (EC) No 765/2008 (paragraph 2). Notifying authorities must be free of conflicts of interest, separate assessment from decision-making, offer no consultancy, protect confidentiality under Article 78 and employ staff competent in information technology, AI, law and fundamental rights (paragraphs 3 to 7). New paragraphs 8 and 9 create a single application and unified assessment procedure for bodies seeking designation under both the Regulation and Annex I Section A legislation.

New paragraphs 8 and 9 introduce a single application and unified assessment procedure for conformity assessment bodies designated under both the Regulation and Annex I Section A harmonisation legislation, administered by the sectoral notifying authority unless the Member State designates another.

Article 29: Application of a Conformity Assessment Body for Notification

applies 2 August 2025amended by 2026/1744Notified bodiesAuthoritiesconformity

Article 29 requires a conformity assessment body to apply to the notifying authority of the Member State where it is established (paragraph 1), describing its conformity assessment activities, modules and the types of AI systems for which it claims competence, and attaching an accreditation certificate showing compliance with Article 31 or, failing that, full documentary evidence (paragraphs 2 and 3). Bodies already designated under other Union harmonisation legislation may reuse those documents, must update the documentation whenever relevant changes occur, and Annex I Section A bodies submit the single application to the sectoral notifying authority under Article 28(8) (paragraph 4). Applicants should prepare an Article 31 evidence pack first.

Paragraph 4 now lets bodies designated under other harmonisation legislation reuse existing designation documents, routes Annex I Section A bodies through the single application under Article 28(8) and adds a duty to update documentation whenever relevant changes occur.

Article 30: Notification Procedure

applies 2 August 2025amended by 2026/1744AuthoritiesNotified bodiesCommissionconformitygovernance

Article 30 allows notifying authorities to notify only conformity assessment bodies that satisfy Article 31 (paragraph 1), using the Commission's electronic notification tool and the codes, categories and AI system types in Annex XIV, which the Commission may amend by delegated act (paragraph 2). The notification states the activities, modules, AI system types and evidence of competence, with documentary proof and monitoring arrangements where no accreditation certificate exists (paragraph 3). The body may act as a notified body only if no objection is raised within two weeks of a notification based on accreditation or two months of one based on documentary evidence (paragraph 4); the Commission decides objections (paragraph 5).

Paragraph 2 now requires notification through the Commission's electronic tool using the codes and categories in new Annex XIV, which the Commission may amend by delegated act, and paragraph 3 is new.

Article 31: Requirements Relating to Notified Bodies

applies 2 August 2025Notified bodiesAuthoritiesconformitygovernance

Sets the conditions a conformity assessment body must meet to be notified: legal personality under national law (paragraph 1), organisational, quality management, resource, process and cybersecurity requirements (2), independence from the providers it assesses and from their competitors (4), no involvement of staff in designing, marketing or using high-risk AI systems, including consultancy (5), confidentiality (7), liability insurance unless the Member State assumes liability (9), sufficient competent personnel (11) and participation in coordination and standardisation work (12). Binds notified bodies and the notifying authorities that vet them. Providers selecting a notified body should check its designation scope against these criteria.

Recitals 145

Article 32: Presumption of Conformity with Requirements Relating to Notified Bodies

applies 2 August 2025Notified bodiesAuthoritiesconformitystandards

Where a conformity assessment body demonstrates conformity with harmonised standards whose references are published in the Official Journal, it is presumed to meet the Article 31 requirements to the extent those standards cover them. Binds notified bodies and the notifying authorities that assess them. Bodies seeking designation should map their accreditation evidence against the relevant published standards, because the presumption reaches only as far as the standards do and the notifying authority must verify the rest directly.

Article 33: Subsidiaries of Notified Bodies and Subcontracting

applies 2 August 2025Notified bodiesconformitygovernance

Allows a notified body to subcontract conformity assessment tasks or use a subsidiary only if the subcontractor or subsidiary meets Article 31 and the notifying authority is informed (paragraph 1). The notified body keeps full responsibility for the work (2), needs the provider's agreement and must publish a list of its subsidiaries (3), and must keep the qualification and work records available to the notifying authority for five years after the subcontracting ends (4). Binds notified bodies. Providers should expect to be asked for consent before any part of their assessment is subcontracted.

Recitals 126

Article 34: Operational Obligations of Notified Bodies

applies 2 August 2025Notified bodiesconformity

Notified bodies verify the conformity of high-risk AI systems using the Article 43 procedures (paragraph 1). They must avoid unnecessary burdens for providers, particularly micro and small enterprises, taking account of provider size, sector, structure and system complexity, while keeping the rigour and level of protection the Regulation requires (2). On request they must submit all relevant documentation, including the provider's documentation, to the notifying authority under Article 28 for its assessment, designation, notification and monitoring work (3). Binds notified bodies. Providers should structure their technical files knowing they may be passed to the notifying authority.

Article 35: Identification Numbers and Lists of Notified Bodies

applies 2 August 2025Commissionconformitygovernance

The Commission assigns each notified body a single identification number, even where the body is notified under more than one Union act (paragraph 1), and publishes and keeps up to date a list of the bodies notified under the Regulation with their numbers and the activities they are notified for (2). Binds the Commission. Providers use the list to confirm that a body is designated for the assessment they need, and the identification number is the one that accompanies the CE marking under Article 48.

Article 36: Changes to Notifications

applies 2 August 2025Notified bodiesAuthoritiesconformitygovernance

Governs changes to a notified body's designation: scope extensions follow Articles 29 and 30. A body ceasing activity gives one year's notice of a planned cessation, and certificates may remain valid for nine months if another body takes over in writing (paragraph 3). Where a body no longer meets Article 31, the notifying authority restricts, suspends or withdraws the designation (4) and the body informs affected providers within 10 days (5). After withdrawal, certificates stay valid for nine months where no risk is confirmed and a replacement body completes reassessment within 12 months (9). Binds notified bodies and authorities; providers should plan for certification continuity.

Article 37: Challenge to the Competence of Notified Bodies

applies 2 August 2025CommissionAuthoritiesNotified bodiesconformityenforcement

The Commission investigates where there is reason to doubt a notified body's competence or its continued compliance with Article 31 (paragraph 1); the notifying authority supplies all relevant information on request (2) and the Commission treats sensitive material confidentially under Article 78 (3). If the body falls short, the Commission asks the notifying Member State to take corrective measures, including suspending or withdrawing the notification, and if the Member State fails to act the Commission may itself suspend, restrict or withdraw the designation by implementing act under the Article 98(2) examination procedure (4). Binds the Commission, notifying authorities and notified bodies.

Article 38: Coordination of Notified Bodies

applies 2 August 2025CommissionNotified bodiesAuthoritiesconformitygovernance

The Commission ensures coordination and cooperation between notified bodies active in conformity assessment of high-risk AI systems through sectoral groups of notified bodies (paragraph 1). Each notifying authority ensures the bodies it designates take part in such a group, directly or through designated representatives (2), and the Commission facilitates the exchange of knowledge and best practice between notifying authorities (3). Binds the Commission, notifying authorities and notified bodies. Providers gain from more consistent assessment practice across bodies and Member States, so divergent interpretations by one body can be raised through the sectoral group.

Article 39: Conformity Assessment Bodies of Third Countries

applies 2 August 2025Notified bodiesCommissionconformityscope

Conformity assessment bodies established under the law of a third country with which the Union has concluded an agreement may be authorised to carry out the activities of notified bodies, provided they meet the Article 31 requirements or ensure an equivalent level of compliance. Binds the Commission and notifying authorities, and third-country bodies seeking authorisation. Providers outside the Union should not assume that a home-country certification body can assess a high-risk AI system unless such an agreement exists and the body has been authorised under it.

Recitals 127

Article 40: Harmonised Standards and Standardisation Deliverables

applies 2 August 2026CommissionProvidersGPAI providersstandardsconformity

High-risk AI systems and general-purpose AI models that conform to harmonised standards published in the Official Journal under Regulation (EU) No 1025/2012 are presumed to comply with the Chapter III Section 2 requirements or the Chapter V Sections 2 and 3 obligations, to the extent the standards cover them (paragraph 1). The Commission must issue standardisation requests covering all those requirements, including reporting and documentation on resource performance such as energy consumption (2). Standardisation participants must promote investment, legal certainty, competitiveness, international alignment, fundamental rights and balanced governance (3). Binds the Commission; providers and GPAI providers should track published references because they are the cheapest route to presumption of conformity.

Recitals 121

Article 41: Common Specifications

applies 2 August 2026CommissionProvidersGPAI providersstandardsconformity

Allows the Commission to adopt implementing acts establishing common specifications for the Section 2 requirements or the Chapter V Sections 2 and 3 obligations, but only where a standardisation request was not accepted, not delivered by the deadline, delivered with fundamental rights shortcomings or not compliant with the request, and no harmonised standard reference is published or expected soon (paragraph 1). Systems and models conforming to common specifications are presumed compliant (3); the specifications are repealed once a harmonised standard covering the same requirements is published (4). Providers not following common specifications must justify that their technical solutions reach an equivalent level (5). Binds the Commission, providers and GPAI providers.

Recitals 121

Article 42: Presumption of Conformity with Certain Requirements

applies 2 August 2026amended by 2026/1744Providersconformitydata

Provides presumptions of conformity for specific requirements. High-risk AI systems trained and tested on data reflecting the geographical, behavioural, contextual or functional setting of intended use are presumed to meet Article 10(4) (paragraph 1). Systems certified under a cybersecurity scheme adopted under Regulation (EU) 2019/881, with references published in the Official Journal, are presumed to meet the Article 15 cybersecurity requirements to the extent covered (2). Systems within the scope of Regulation (EU) 2024/2847 that fulfil the conditions in its Article 12(1) are deemed to comply with Article 15 (3). Binds providers; use existing cybersecurity certification and Cyber Resilience Act compliance to discharge Article 15 rather than duplicating evidence.

Adds a new paragraph 3 deeming high-risk AI systems within the scope of Regulation (EU) 2024/2847 that meet the conditions of its Article 12(1) to comply with the Article 15 cybersecurity requirements.

Recitals 77, 78, 122

Article 43: Conformity Assessment

applies 2 August 2026amended by 2026/1744ProvidersNotified bodiesconformityprovider duties

Sets the conformity assessment route. For Annex III point 1 biometric systems, providers applying harmonised standards or common specifications choose internal control under Annex VI or notified body assessment under Annex VII; otherwise Annex VII is mandatory (paragraph 1). Annex III points 2 to 8 systems use internal control under Annex VI (2). Annex I Section A products follow their sectoral procedure with the Section 2 requirements folded in; sectoral notified bodies may assess them and must apply for designation by 28 January 2028 (3). Substantial modification triggers a new assessment, except pre-determined changes documented in the technical file (4). Binds providers and notified bodies.

Paragraph 3 was amended so that notified bodies under Annex I Section A legislation must apply for designation under Section 4 by 28 January 2028, and new subparagraphs let manufacturers who applied harmonised standards covering all Section 2 requirements avoid third-party assessment and settle which procedure applies where a system falls under both Annex I and Annex III.

Recitals 78, 123, 124, 125, 126, 128, 147

Article 44: Certificates

applies 2 August 2026Notified bodiesProvidersconformity

Certificates issued under Annex VII must be drawn up in a language easily understood by the authorities of the notified body's Member State (paragraph 1). They are valid for at most five years for Annex I systems and four years for Annex III systems, renewable for equivalent periods after reassessment, and supplements remain valid while the main certificate does (2). Where a system no longer meets the Section 2 requirements, the body suspends, withdraws or restricts the certificate unless the provider corrects within a set deadline, gives written reasons, and an appeal procedure must be available (3). Binds notified bodies; providers should diarise renewal well before expiry.

Article 45: Information Obligations of Notified Bodies

applies 2 August 2026Notified bodiesconformitygovernance

Notified bodies must inform their notifying authority of every Union technical documentation assessment certificate, supplement and quality management system approval issued under Annex VII, of any refusal, restriction, suspension or withdrawal, of circumstances affecting their notification and of information requests from market surveillance authorities (paragraph 1). They must tell other notified bodies about refused, suspended or withdrawn approvals and certificates, and on request about those issued (2), and share information on negative results with bodies assessing the same types of AI systems (3), all under Article 78 confidentiality (4). Binds notified bodies; providers should expect a refusal by one body to be known to the others.

Article 46: Derogation from Conformity Assessment Procedure

applies 2 August 2026AuthoritiesDeployersconformityenforcement

Lets a market surveillance authority authorise placing a specific high-risk AI system on the market or into service without completing conformity assessment, for exceptional reasons of public security, protection of life and health, environmental protection or protection of key industrial and infrastructural assets, only while the assessment is carried out. Law enforcement may use a system in urgent situations without prior authorisation if it requests one immediately afterwards; if refused, use stops and outputs are discarded. The authority verifies Section 2 compliance and notifies the Commission and Member States; absent objections within 15 days the authorisation stands. Annex I Section A products use only sectoral derogations. Binds authorities and deployers.

Recitals 130

Article 47: EU Declaration of Conformity

applies 2 August 2026Providersconformityprovider duties

Providers must draw up a written, machine-readable, physical or electronically signed EU declaration of conformity for each high-risk AI system, keep it for 10 years after placing on the market or putting into service and supply it to national competent authorities on request (paragraph 1). It states conformity with Section 2, contains the Annex V information and is translated into a language the relevant authorities understand (2). Where other Union harmonisation legislation also requires one, a single declaration covers all applicable law (3). By drawing it up the provider assumes responsibility for compliance and must keep it current (4). Binds providers.

Article 48: CE Marking

applies 2 August 2026Providersconformityprovider duties

The CE marking signals conformity with Chapter III Section 2 and other applicable Union harmonisation legislation and follows the general principles in Article 30 of Regulation (EC) No 765/2008 (paragraph 1). For systems provided digitally, a digital CE marking is allowed if it is easily accessed through the interface or a machine-readable code (2). The marking must be visible, legible and indelible, or placed on packaging or documentation where that is impossible (3), and must carry the notified body's identification number where one was involved, including in promotional material claiming compliance (4). Binds providers; do not affix the marking before the conformity assessment and declaration are complete.

Recitals 129

Article 49: Registration

applies 2 August 2026ProvidersDeployersregistrationprovider duties

Before placing on the market or putting into service an Annex III high-risk AI system, other than point 2 critical infrastructure systems, the provider or authorised representative registers itself and the system in the EU database under Article 71 (paragraph 1). Providers who conclude under Article 6(3) that a system is not high-risk must also register it (2). Public authority and Union body deployers register themselves and the use of the system before use (3). Law enforcement, migration, asylum and border control systems under points 1, 6 and 7 go in a secure non-public section (4); point 2 systems are registered nationally (5). Binds providers and public deployers.

Recitals 131

Chapter IV: Transparency Obligations for Providers and Deployers of Certain AI Systems1 provision

Article 50: Transparency Obligations for Providers and Deployers of Certain AI Systems

applies 2 August 2026amended by 2026/1744ProvidersDeployerstransparencyprovider dutiesdeployer duties

Providers must design AI systems that interact directly with people so that those people know they are dealing with AI, unless that is obvious (paragraph 1), and must mark synthetic audio, image, video or text output in a machine-readable, detectable way as far as technically feasible (2). Deployers of emotion recognition or biometric categorisation systems must inform exposed persons (3) and must disclose deep fakes and AI-generated text published on matters of public interest, with exceptions for artistic works and text under editorial responsibility (4). Information is given clearly at the first interaction or exposure (5). Uses authorised by law for criminal offences are exempt. Binds providers and deployers.

Paragraph 7 was amended: the Commission may now approve codes of practice on detection and labelling of AI-generated content by implementing act under the Article 56(6) procedure, and may set common rules by implementing act if it finds a code inadequate.

Recitals 120, 132, 133, 134, 135, 136, 137

Chapter V: General-Purpose AI Models6 provisions

Article 51: Classification of General-Purpose AI Models as General-Purpose AI Models with Systemic Risk

applies 2 August 2025GPAI providersCommissiongpaihigh risk classification

A general-purpose AI model is classified as having systemic risk if it has high-impact capabilities assessed with technical tools, indicators and benchmarks, or if the Commission so decides ex officio or after a qualified alert from the scientific panel, using the Annex XIII criteria (paragraph 1). High-impact capabilities are presumed where cumulative training compute exceeds 10^25 floating point operations (2). The Commission may amend the thresholds and supplement benchmarks and indicators by delegated act to track algorithmic and hardware progress (3). Binds GPAI providers and the Commission; providers should track cumulative training compute against the 10^25 line, since crossing it triggers the Article 52 notification duty.

Recitals 110, 111

Article 52: Procedure

applies 2 August 2025GPAI providersCommissiongpaigovernance

A provider whose model meets the Article 51(1)(a) condition must notify the Commission within two weeks of meeting it or learning it will be met, with supporting information (paragraph 1). The provider may argue that the model exceptionally presents no systemic risk (2); if the Commission rejects the arguments the classification stands (3). The Commission may designate a model ex officio or after a qualified alert from the scientific panel using Annex XIII (4). A provider may request reassessment at the earliest six months after designation on new, objective grounds (5). The Commission publishes an up-to-date list of systemic-risk models (6). Binds GPAI providers and the Commission.

Recitals 112, 113

Article 53: Obligations for Providers of General-Purpose AI Models

applies 2 August 2025GPAI providersgpaiprovider duties

Providers of general-purpose AI models must keep technical documentation with at least the Annex XI content for the AI Office and national authorities (paragraph 1(a)), give downstream AI system providers the Annex XII information they need to comply (1(b)), adopt a copyright policy that respects rights reservations under Article 4(3) of Directive (EU) 2019/790 (1(c)) and publish a sufficiently detailed summary of training content using the AI Office template (1(d)). Points (a) and (b) do not apply to free and open-source models with public weights and architecture, unless the model has systemic risk (2). Codes of practice under Article 56 or harmonised standards demonstrate compliance (4). Binds GPAI providers.

Recitals 101, 102, 103, 104, 105, 106, 107, 108, 109

Article 54: Authorised Representatives of Providers of General-Purpose AI Models

applies 2 August 2025GPAI providersgpaiprovider duties

Third-country providers must appoint, by written mandate, an authorised representative established in the Union before placing a general-purpose AI model on the market (paragraph 1). The representative verifies that the Annex XI technical documentation was drawn up and that Articles 53 and 55 are met, keeps the documentation available to the AI Office and national authorities for 10 years, and cooperates with authorities, which may address it instead of the provider (3 and 4). It may terminate the mandate, informing the AI Office (5). The duty does not apply to free and open-source models with public parameters unless they carry systemic risk (6). Binds GPAI providers and their representatives.

Article 55: Obligations of Providers of General-Purpose AI Models with Systemic Risk

applies 2 August 2025GPAI providersgpaiincidents

Providers of general-purpose AI models with systemic risk must, in addition to Articles 53 and 54, evaluate the model with standardised protocols including adversarial testing (paragraph 1(a)), assess and mitigate possible systemic risks at Union level from development, placing on the market or use (1(b)), track, document and report serious incidents and corrective measures to the AI Office and where relevant national authorities without undue delay (1(c)), and ensure adequate cybersecurity for the model and its physical infrastructure (1(d)). Codes of practice under Article 56 or harmonised standards demonstrate compliance; otherwise the provider shows alternative adequate means (2). Binds GPAI providers of systemic-risk models.

Recitals 114, 115

Article 56: Codes of Practice

applies 2 August 2025amended by 2026/1744GPAI providersCommissiongpaistandards

Tasks the AI Office with facilitating Union-level codes of practice for the Article 53 and 55 obligations, covering documentation upkeep, training content summaries, and the identification and management of systemic risks (paragraphs 1 and 2). Participants report against key performance indicators scaled to their size (5). The Commission and the Board monitor the codes and publish an adequacy assessment, and the Commission may approve a code by implementing act, giving it general validity (6). Codes were due by 2 May 2025; if none was adequate by 2 August 2025 the Commission may set common rules by implementing act (9). Binds GPAI providers and the Commission.

Paragraph 6 was amended to revise how the Commission and the Board monitor and evaluate the codes and to confirm that the Commission approves a code and gives it general validity by implementing act under the Article 98(2) examination procedure.

Recitals 116, 117

Chapter VI: Measures in Support of Innovation8 provisions

Article 57: AI Regulatory Sandboxes

applies 2 August 2026amended by 2026/1744AuthoritiesProvidersCommissionsandboxes

Member States must have at least one national AI regulatory sandbox operational by 2 August 2026 (paragraph 1); the European Data Protection Supervisor may run one for Union bodies (3) and the AI Office may run a Union-level sandbox for Article 75(1) systems with priority access for SMEs and SMCs (3a). Sandboxes provide a controlled environment for developing and testing AI systems under an agreed plan, which may include real-world testing (5). Participants receive an exit report that notified bodies and market surveillance authorities take positively into account (7). No administrative fines apply to participants who follow the plan in good faith (12). Binds authorities and providers.

Adds paragraph 3a allowing the AI Office to establish a Union-level sandbox for Article 75(1) systems with priority access for SMEs and SMCs, requires sandbox plans to incorporate the Article 60 and 60a real-world testing plans, adds SMCs to the objectives and strengthens coordination with the AI Office.

Recitals 138, 139

Article 58: Detailed Arrangements for, and Functioning of, AI Regulatory Sandboxes

applies 2 August 2026amended by 2026/1744CommissionAuthoritiessandboxesgovernance

Requires the Commission to adopt implementing acts under the Article 98(2) examination procedure setting common principles for sandbox eligibility and selection criteria, application, monitoring, exit and termination procedures, participant terms and conditions, and the governance of sandboxes including data protection authority involvement and coordination at national and Union level (paragraph 1). Those acts must ensure open, transparent and fair selection with a decision within three months of application, free access for SMEs and start-ups apart from exceptional costs, mutual recognition of participation across the Union and time-limited participation proportionate to the project (2). Binds the Commission and national competent authorities; providers should use the learning outcomes to support conformity assessment.

Paragraph 1(a) was amended and a new point 1(d) requires the implementing acts to set detailed governance rules for sandboxes, including data protection authority involvement and coordination at national and Union level.

Recitals 139

Article 59: Further Processing of Personal Data for Developing Certain AI Systems in the Public Interest in the AI Regulatory Sandbox

applies 2 August 2026ProvidersAuthoritiessandboxesdata

Permits, within a sandbox, further processing of personal data collected for other purposes to develop, train and test AI systems serving a substantial public interest in public safety and health, environment and climate, energy, transport and critical infrastructure, or public administration (paragraph 1(a)). All conditions must hold: other data will not suffice (b), risks are monitored (c), processing stays in a separate, protected environment (d), created data stay inside (e), no measures affect data subjects (f), data are deleted when participation ends (g), with logs, Annex IV documentation and a published summary (h to j). Law enforcement processing needs a legal basis (2). Binds providers and public authorities.

Recitals 140

Article 60: Testing of High-Risk AI Systems in Real World Conditions Outside AI Regulatory Sandboxes

applies 2 August 2026amended by 2026/1744ProvidersAuthoritiessandboxesoversight

Providers and prospective providers of Annex III high-risk AI systems, and of Annex I Section A products, may test in real-world conditions outside a sandbox under a testing plan whose elements the Commission specifies by implementing act (paragraph 1). Conditions include submitting the plan to the market surveillance authority, with approval deemed after 30 days, registration with a Union-wide identification number, Union establishment or a legal representative, a maximum of six months extendable by six, protection of vulnerable groups, Article 61 consent and reversible outputs (4). Subjects may withdraw at any time (5), serious incidents are reported under Article 73 (7) and the provider stays liable (9). Binds providers.

Paragraphs 1 and 2 were amended to extend real-world testing outside sandboxes to high-risk AI systems covered by the Union harmonisation legislation in Annex I Section A, without prejudice to sectoral rules on such testing.

Recitals 141

Article 60a: Testing of high-risk AI systems covered by Union harmonisation legislation listed in Section B of Annex I in real-world conditions outside AI regulatory sandboxes

applies 27 July 2026amended by 2026/1744ProvidersAuthoritiesCommissionsandboxesconformityscope

Article 60a lets Member States allow providers or prospective providers of AI-enabled products under Annex I Section B legislation to test high-risk AI systems in real-world conditions outside sandboxes, to verify conformity with Articles 8 to 15 (paragraph 1). A Member State that opts in adopts a testing framework, alone or jointly, notifies the Commission before applying it and makes its authorities cooperate to remove practical obstacles (paragraphs 2 to 4). Each framework requires a mandatory testing plan agreed with the national competent or market surveillance authority, compliance with Article 60(2), (3), (4)(d) to (j) and (5) to (9), governance and accountability arrangements and a high level of protection of health, safety and fundamental rights (paragraph 5). Testing is not placing on the market, and sectoral legislation prevails (paragraph 6).

Inserted by Regulation (EU) 2026/1744: it creates an optional national real-world testing route for Annex I Section B products, which Article 2(2) now lists among the few provisions applying to those products.

Article 61: Informed Consent to Participate in Testing in Real World Conditions Outside AI Regulatory Sandboxes

applies 2 August 2026Providerssandboxestransparency

Before a person takes part in real-world testing under Article 60, the provider must obtain freely given informed consent, having given concise, clear, relevant and understandable information on the nature and objectives of the testing and any possible inconvenience (paragraph 1(a)), the conditions and expected duration (b), the right to refuse or withdraw without detriment (c), the arrangements for reversing or disregarding the system's outputs (d), and the Union-wide testing identification number and provider contact details (e). Consent must be dated and documented, with a copy given to the subject or legal representative (2). Binds providers and prospective providers; build the consent record into the testing plan before submission.

Recitals 141

Article 62: Measures for Providers and Deployers, in Particular SMEs, Including Start-Ups

applies 2 August 2026AuthoritiesCommissionsandboxesother

Member States must give SMEs and start-ups with a registered office or branch in the Union priority access to regulatory sandboxes (paragraph 1(a)), run awareness and training activities on the Regulation tailored to them (b), use dedicated channels to communicate with them (c) and support their participation in standardisation (d). Conformity assessment fees must take account of the specific interests and needs of SME providers (2). The AI Office provides standardised templates, a single information platform, awareness campaigns and an evaluation of public procurement practice for AI systems (3). Binds Member States and the AI Office; small providers should ask their national authority about sandbox priority and fee arrangements.

Recitals 143

Article 63: Derogations for Specific Operators

applies 2 August 2026amended by 2026/1744Providersprovider dutiesother

SMEs, including start-ups, may comply with certain elements of the Article 17 quality management system in a simplified manner, provided they have no partner or linked enterprises within the meaning of Recommendation 2003/361/EC; the Commission issues guidelines identifying those elements without lowering the level of protection (paragraph 1). The simplification does not exempt them from any other requirement, including Articles 9 to 15, 72 and 73 (2). Binds providers that are SMEs. Small providers of high-risk AI systems must still document risk management, data governance, logging, human oversight, post-market monitoring and incident reporting in full.

Paragraph 1 was amended to extend the simplified quality management system option from microenterprises to all SMEs including start-ups.

Recitals 146

Chapter VII: Governance7 provisions

Article 64: AI Office

applies 2 August 2025amended by 2026/1744CommissionInstitutionalgovernance

The Commission develops Union expertise and capabilities in AI through the AI Office (paragraph 1), Member States facilitate the tasks entrusted to it (2), and the AI Office must be allocated adequate resources to perform its duties and exercise its enforcement powers (3). Concerns the Commission and Member States. Practitioners deal with the AI Office as the supervisor of general-purpose AI models, the facilitator of codes of practice and, following the Omnibus, the possible operator of a Union-level sandbox.

Adds a new paragraph 3 requiring the AI Office to be allocated adequate resources to perform its duties and exercise its enforcement powers.

Article 65: Establishment and Structure of the European Artificial Intelligence Board

applies 2 August 2025Institutionalgovernance

Establishes the European Artificial Intelligence Board, composed of one representative per Member State with the European Data Protection Supervisor as observer and the AI Office attending without a vote (paragraphs 1 and 2). Representatives serve three years, renewable once (3), act as single contact points for their Member State (4) and adopt rules of procedure by a two-thirds majority (5). The Board runs two standing sub-groups, on market surveillance and on notified bodies, the former acting as the administrative cooperation group under Regulation (EU) 2019/1020 (6). A Member State representative chairs and the AI Office provides the secretariat (8). Institutional; its guidance shapes how national authorities apply the Regulation.

Recitals 149

Article 66: Tasks of the Board

applies 2 August 2025InstitutionalAuthoritiesgovernance

The European Artificial Intelligence Board advises and assists the Commission and the Member States to secure consistent and effective application of the Regulation. Its tasks in points (a) to (o) include coordinating national competent authorities and joint market surveillance activities under Article 74(11), advising on codes of practice and Commission guidelines, opining on harmonised standards under Articles 40 and 41, on amendments to Annex III under Article 7 and on qualified alerts about general-purpose AI models. Practitioners treat Board opinions and recommendations as the earliest signal of how authorities will read contested provisions.

Recitals 149

Article 67: Advisory Forum

applies 2 August 2025InstitutionalCommissiongovernance

An advisory forum supplies technical expertise to the Board and the Commission. Paragraph 2 requires balanced membership across industry, start-ups, SMEs, civil society and academia; the Commission appoints members for two-year terms extendable to no more than four years, and the Fundamental Rights Agency, ENISA, CEN, CENELEC and ETSI sit as permanent members (paragraph 5). The forum meets at least twice a year, may form sub-groups and publishes an annual report (paragraphs 7, 9 and 10). Industry bodies seeking influence on guidance and codes should engage through it.

Recitals 150

Article 68: Scientific Panel of Independent Experts

applies 2 August 2025CommissionInstitutionalGPAI providersgovernancegpai

The Commission establishes by implementing act a scientific panel of independent experts to support enforcement, chosen for AI expertise and independence from providers, with fair gender and geographical representation (paragraphs 1 and 2). The panel advises the AI Office on systemic risks of general-purpose AI models, on evaluation tools and methodologies, on classifying models with systemic risk and on cross-border market surveillance (paragraph 3), and it can issue the qualified alerts that trigger Article 90. Members act independently, declare interests publicly and keep information confidential (paragraph 4). Providers of general-purpose AI models should expect panel input behind any AI Office evaluation.

Recitals 151

Article 69: Access to the Pool of Experts by the Member States

applies 2 August 2025amended by 2026/1744AuthoritiesCommissiongovernanceenforcement

Member States may call on the scientific panel's experts to support their own enforcement work (paragraph 1) and may be charged fees at the rate the Commission pays under the Article 68(1) implementing act (paragraph 2). The Commission facilitates timely access and organises the combination of expert support and the Union AI testing support structures under Article 84 so that it adds the most value (paragraph 3). National authorities investigating complex systems can draw on Union-level technical capacity rather than building it alone.

Paragraph 3 is marked as amended, adjusting how the Commission organises expert access alongside the Union AI testing support structures under Article 84.

Recitals 151

Article 70: Designation of National Competent Authorities and Single Points of Contact

applies 2 August 2025amended by 2026/1744AuthoritiesInstitutionalgovernance

Each Member State designates at least one notifying authority and at least one market surveillance authority, acting independently and impartially (paragraph 1), and names one market surveillance authority as single point of contact, with contact details published by 2 August 2025 (paragraph 2). Authorities need adequate technical, financial and human resources with expertise spanning AI, data protection, cybersecurity and fundamental rights, reviewed annually (paragraph 3), and Member States report on resources by 2 August 2025 and every two years (paragraph 6). Authorities may guide SMEs, start-ups and SMCs (paragraph 8); the European Data Protection Supervisor supervises Union institutions (paragraph 9). Operators should identify their national single point of contact now.

Paragraph 8 is amended so that national guidance and advice extends to SMCs (small mid-caps) alongside SMEs and start-ups.

Recitals 153, 154

Chapter VIII: EU Database for High-Risk AI Systems1 provision

Article 71: EU Database for High-Risk AI Systems Listed in Annex III

applies 2 August 2026CommissionProvidersDeployersregistrationgovernance

The Commission, with the Member States, runs an EU database of high-risk AI systems under Article 6(2) registered under Articles 49 and 60, and of systems the provider judges non-high-risk under Article 6(3) and registers under Article 6(4) (paragraph 1). Providers or authorised representatives enter Annex VIII Sections A and B data; deployers that are public authorities enter Section C (paragraphs 2 and 3). Article 49 registrations are public and machine-readable, while Article 60 real-world testing entries stay restricted to authorities unless the provider consents (paragraph 4). The Commission is controller (paragraph 6). Providers should prepare Annex VIII content before placing systems on the market.

Recitals 131

Chapter IX: Post-Market Monitoring, Information Sharing and Market Surveillance27 provisions

Article 72: Post-Market Monitoring by Providers and Post-Market Monitoring Plan for High-Risk AI Systems

applies 2 August 2026amended by 2026/1744Providersprovider dutiesoversight

Providers must establish and document a post-market monitoring system proportionate to the AI technology and the risks of the high-risk system (paragraph 1), which actively collects and analyses performance data across the system's lifetime to verify continued compliance with Chapter III, Section 2 (paragraph 2). The system rests on a post-market monitoring plan forming part of the Annex IV technical documentation, with Commission guidance and a template due by 2 September 2027 (paragraph 3). Providers covered by Annex I, Section A legislation or Annex III, point 5 financial rules may integrate the elements into existing systems (paragraph 4). Build the plan into the technical file from day one.

Paragraph 3 replaces the implementing act on a monitoring plan template that was due by 2 February 2026 with Commission guidance, including a template, adopted after taking utmost account of the Board's opinion by 2 September 2027.

Recitals 155

Article 73: Reporting of Serious Incidents

applies 2 August 2026ProvidersAuthoritiesincidentsprovider duties

Providers of high-risk AI systems report any serious incident to the market surveillance authority of the Member State where it occurred (paragraph 1). The deadline is immediately after establishing a causal link or a reasonable likelihood of one, and no later than 15 days after awareness (paragraph 2), shortened to two days for widespread infringements or Article 3(49)(b) incidents (paragraph 3) and ten days for a death (paragraph 4); an incomplete initial report may be filed (paragraph 5). Providers investigate and cooperate without altering the system in ways that hinder evaluation (paragraph 6). Systems under equivalent sectoral reporting regimes report only Article 3(49)(c) incidents (paragraphs 9 and 10).

Recitals 155

Article 74: Market Surveillance and Control of AI Systems in the Union Market

applies 2 August 2026AuthoritiesProvidersenforcementoversight

Regulation (EU) 2019/1020 governs market surveillance of AI systems, with providers, deployers, importers, distributors and authorised representatives all counted as economic operators (paragraph 1). Sectoral authorities under Annex I, Section A legislation, financial supervisors for financial institutions (paragraph 6) and data protection authorities for Annex III points 1, 6, 7 and 8 systems (paragraph 8) act as market surveillance authorities; the European Data Protection Supervisor covers Union institutions (paragraph 9). Authorities get full access to documentation and to training, validation and testing data sets, including remotely via APIs (paragraph 12), and to source code on reasoned request once other verification is exhausted (paragraph 13).

Recitals 156, 158, 159, 160

Article 75: Market Surveillance and Control of AI Systems and Mutual Assistance

applies 2 August 2026amended by 2026/1744CommissionAuthoritiesProvidersenforcementgpaigovernance

The AI Office holds exclusive competence to supervise and enforce obligations for AI systems built on a general-purpose AI model where the same provider develops both, and for AI systems embedded in very large online platforms or search engines designated under Regulation (EU) 2022/2065 (paragraph 1). Providers under AI Office competence report serious incidents to the AI Office (paragraph 1a); national authorities assist it and are consulted before restrictive measures (paragraphs 1b to 1d); it runs third-party conformity assessments at the provider's cost (paragraph 1e). Authorities may refer suspected infringements, with a four-month response, and obtain model information within 30 days (paragraphs 2a and 3).

Substantially rewritten: paragraph 1 gives the AI Office exclusive competence over AI systems built on a provider's own general-purpose AI model and over systems in designated very large online platforms and search engines, and new paragraphs 1a to 1e and 2a add incident reporting to the AI Office, mutual assistance, consultation, AI Office conformity assessment and a referral procedure with a four-month answer.

Recitals 161

Article 75a: Supervisory and enforcement powers of the AI Office

applies 27 July 2026amended by 2026/1744CommissionProvidersDeployersenforcementgovernance

Article 75a gives the AI Office, for the operators it supervises under Article 75(1), all the powers of a market surveillance authority under Section 3 and Articles 14(4) and 16(3) of Regulation (EU) 2019/1020, plus recovery of its full enforcement costs from non-compliant operators (paragraph 1). It may open an investigation on reasonable grounds or after an Article 85 complaint (paragraph 2), request information by simple request or decision, stating the Article 99(5) fines for incorrect answers (paragraph 3), and conduct remote or on-site inspections, entering premises, copying records and sealing premises, with judicial authorisation where national law requires it (paragraph 4). National authorities may investigate on its behalf, it may order access to systems and appoint external experts, and collected information serves only the Regulation (paragraphs 5 to 8).

Inserted by Regulation (EU) 2026/1744: it gives the AI Office direct investigation, information request and inspection powers over the operators assigned to it by Article 75(1), mirroring the powers of national market surveillance authorities.

Article 75b: Commitments

applies 27 July 2026amended by 2026/1744CommissionProvidersDeployersenforcement

Article 75b lets an operator under Article 75a(2) proceedings offer commitments to bring itself into compliance, and lets the AI Office make those commitments binding by decision and declare that there are no further grounds for action. The AI Office may reopen the proceedings, on request or on its own initiative, where the facts have materially changed, the operator acts contrary to its commitments, or the decision rested on incomplete, incorrect or misleading information from the operator (points (a) to (c)). Where the commitments cannot ensure effective compliance, the AI Office rejects them in a reasoned decision when closing the proceedings. Operators should draft commitments that are verifiable, because breach triggers fines and periodic penalty payments under Article 75c.

Inserted by Regulation (EU) 2026/1744: it adds a competition-law style commitments procedure allowing the AI Office to close an investigation by making an operator's offered remedies binding.

Article 75c: Non-compliance, fines and periodic penalty payments

applies 27 July 2026amended by 2026/1744CommissionProvidersDeployersenforcementpenalties

Article 75c sets the AI Office's sanction procedure for Article 75(1) operators. After preliminary findings it adopts a non-compliance decision ordering measures within a reasonable period and may hold a structured dialogue in which Article 75b commitments are offered (paragraphs 1 to 3). The decision may carry administrative fines under Article 99(3) to (7) for infringing the Regulation, ignoring measures under Articles 14(4) or 16(3) of Regulation (EU) 2019/1020 or Article 75a, or breaching commitments, and misleading information attracts Article 99(5) fines (paragraph 4). Periodic penalty payments of up to 5% of average daily income or worldwide annual turnover per day compel cooperation and compliance (paragraph 5). The Court of Justice has unlimited jurisdiction, fines go to the Union budget and a five-year limitation period applies (paragraphs 6 to 8).

Inserted by Regulation (EU) 2026/1744: it gives the AI Office its own power to find non-compliance, impose Article 99 fines and levy periodic penalty payments of up to 5% of daily turnover on the operators it supervises.

Article 75d: Safeguards and further specification

applies 27 July 2026amended by 2026/1744CommissionProvidersDeployersenforcementgovernance

Article 75d supplies the procedural safeguards for operators facing AI Office enforcement under Article 75(1). Article 18 of Regulation (EU) 2019/1020 applies mutatis mutandis (paragraph 1). Rights of defence and access to the file are fully respected: before an Article 75c(1) decision the operator gets access to the AI Office file under negotiated disclosure terms that protect business secrets, with the AI Office fixing the terms if the parties disagree, while confidential information, internal documents and correspondence with national authorities stay outside the right of access (paragraph 2). The Commission may adopt implementing acts on file access arrangements (paragraph 3). The AI Office publishes its Article 75b and 75c decisions, naming the parties and stating the main content and any penalties, with regard to confidential information (paragraph 4).

Inserted by Regulation (EU) 2026/1744: it adds rights of defence, negotiated access to the file, an implementing act power and mandatory publication of AI Office decisions to the new direct enforcement regime.

Article 76: Supervision of Testing in Real World Conditions by Market Surveillance Authorities

applies 2 August 2026amended by 2026/1744AuthoritiesProviderssandboxesenforcementoversight

Market surveillance authorities hold the competences and powers to ensure that testing in real world conditions complies with the Regulation (paragraph 1). For testing inside an AI regulatory sandbox under Article 58 they check compliance with Article 60 and may permit derogations from Article 60(4), points (f) and (g) (paragraph 2). On a serious incident or grounds of non-compliance with Articles 60 and 61 they may suspend or terminate the testing or require modifications (paragraph 3), giving reasons and a route to challenge (paragraph 4) and informing other Member States named in the testing plan (paragraph 5). Providers testing in real world conditions should keep a live compliance file.

Paragraph 1 adds that for testing under Article 60a references to market surveillance authorities mean the national competent authorities, or the European Data Protection Supervisor for Union institutions.

Article 77: Powers of Authorities Protecting Fundamental Rights and Cooperation with Market Surveillance Authorities

applies 2 August 2026amended by 2026/1744AuthoritiesDeployersenforcementoversight

National authorities protecting fundamental rights may request and access any documentation created or held under the Regulation, in accessible and machine-readable form, when needed for their mandate (paragraph 1). Market surveillance authorities must grant that access without undue delay, requesting it from providers or deployers where necessary (paragraph 1a), and both sets of authorities cooperate closely and coordinate procedures (paragraph 1b). Member States published their list of such authorities by 2 November 2024 (paragraph 2). Where documentation is insufficient, a fundamental rights authority may ask for technical testing of a high-risk system (paragraph 3). Deployers in employment or public services should expect equality bodies among their supervisors.

Paragraph 1a is amended to oblige market surveillance authorities to grant fundamental rights authorities access without undue delay, and new paragraph 1b requires close cooperation, information exchange and coordination between the two sets of authorities.

Recitals 157

Article 78: Confidentiality

applies 2 August 2026AuthoritiesNotified bodiesCommissionenforcementoversight

The Commission, market surveillance authorities, notified bodies and everyone else involved in applying the Regulation must protect intellectual property, trade secrets including source code, the integrity of inspections, public and national security, criminal and administrative proceedings and classified information (paragraph 1). Authorities request only data strictly necessary to assess risk, secure it with adequate cybersecurity and delete it once no longer needed (paragraph 2). Confidential exchanges between authorities are not disclosed without consulting the originator; law enforcement, immigration and asylum providers keep technical documentation on their premises for cleared staff (paragraph 3). Article 113(b) lists Article 78 among the provisions applying from 2 August 2025.

Recitals 167

Article 79: Procedure at National Level for Dealing with AI Systems Presenting a Risk

applies 2 August 2026AuthoritiesProvidersenforcement

An AI system presenting a risk to health, safety or fundamental rights counts as a product presenting a risk under Regulation (EU) 2019/1020 (paragraph 1). Market surveillance authorities evaluate suspect systems and, on finding non-compliance, require the operator to correct, withdraw or recall within a period no longer than 15 working days (paragraph 2), and take provisional measures if the operator fails to act (paragraph 5). Notifications specify whether the breach concerns Article 5, Chapter III, Section 2, harmonised standards or Article 50 (paragraph 6); measures stand if no objection arrives within three months, or 30 days for Article 5 breaches (paragraph 8). Operators need a Union-wide corrective action capability.

Article 80: Procedure for Dealing with AI Systems Classified by the Provider as Non-High-Risk in Application of Annex III

applies 2 August 2026AuthoritiesProvidershigh risk classificationenforcementpenalties

Market surveillance authorities may evaluate any system a provider has classified as non-high-risk under Article 6(3) and, applying the Article 6 criteria and Commission guidelines, decide whether it is in fact high-risk (paragraph 1). If so, the provider must bring the system into compliance and take corrective action within a set period (paragraph 2), across all affected systems on the Union market (paragraph 5); failure triggers the Article 79(5) to (9) measures (paragraph 6). Deliberate misclassification to escape Chapter III, Section 2 attracts fines under Article 99 (paragraph 7). Authorities may run checks using the Article 71 database (paragraph 8). Providers relying on Article 6(3) need a documented, defensible assessment.

Article 81: Union Safeguard Procedure

applies 2 August 2026CommissionAuthoritiesenforcement

Where a Member State objects within three months, or 30 days for Article 5 breaches, to another Member State's measure under Article 79(5), or the Commission considers a measure contrary to Union law, the Commission consults the authorities and operators and decides within six months, or 60 days for Article 5 breaches, whether the measure is justified (paragraph 1). A justified measure must be mirrored by every Member State; an unjustified one is withdrawn (paragraph 2). Where the shortfall lies in a harmonised standard or common specification, the Commission applies Article 11 of Regulation (EU) No 1025/2012 (paragraph 3). Operators contesting a national ban should engage in the Commission consultation.

Article 82: Compliant AI Systems Which Present a Risk

applies 2 August 2026AuthoritiesProvidersCommissionenforcement

A high-risk AI system that complies with the Regulation can still be stopped: where a market surveillance authority finds it presents a risk to health, safety, fundamental rights or other public interests, it requires the operator to remove the risk without undue delay within a set period (paragraph 1), and the provider applies corrective action to all affected systems on the Union market (paragraph 2). The Member State informs the Commission and the other Member States, giving system identification, origin, supply chain, the risk and the measures taken (paragraph 3); the Commission evaluates and may propose further measures (paragraphs 4 and 5). Conformity is necessary but not sufficient.

Article 83: Formal Non-Compliance

applies 2 August 2026AuthoritiesProvidersconformityenforcement

Market surveillance authorities order the provider to end formal non-compliance where the CE marking is affixed in breach of Article 48 or missing, the EU declaration of conformity is absent or wrongly drawn up, the EU database registration is missing, no authorised representative is appointed where required, or technical documentation is unavailable (paragraph 1). If non-compliance persists, the authority restricts or prohibits the high-risk system or has it recalled or withdrawn without delay (paragraph 2). Providers should run a pre-market checklist covering marking, declaration, registration, representative and technical file.

Article 84: Union AI Testing Support Structures

applies 2 August 2026CommissionAuthoritiesgovernanceenforcement

The Commission designates one or more Union AI testing support structures to perform the tasks listed in Article 21(6) of Regulation (EU) 2019/1020 in the field of AI (paragraph 1). Beyond that, the structures give independent technical or scientific advice at the request of the Board, the Commission or market surveillance authorities (paragraph 2). They complement the scientific panel's experts under Article 69 and give national authorities a shared testing capacity for complex systems, so providers may meet them during investigations.

Recitals 152

Article 85: Right to Lodge a Complaint with a Market Surveillance Authority

applies 2 August 2026EveryoneAuthoritiesenforcement

Any natural or legal person with grounds to consider that the Regulation has been infringed may lodge a complaint with the relevant market surveillance authority, without prejudice to other administrative or judicial remedies (paragraph 1). Authorities handle complaints under the procedures of Regulation (EU) 2019/1020 and take them into account in their surveillance activities (paragraph 2). Civil society organisations, competitors and affected individuals gain a formal route into enforcement, so operators should expect complaints to trigger evaluations under Article 79.

Recitals 170

Article 86: Right to Explanation of Individual Decision-Making

applies 2 August 2026DeployersEveryonedeployer dutiestransparency

Any affected person subject to a decision taken by a deployer on the basis of the output of an Annex III high-risk AI system, other than point 2 critical infrastructure, that produces legal effects or similarly significantly affects their health, safety or fundamental rights may obtain from the deployer clear and meaningful explanations of the AI system's role in the decision procedure and the main elements of the decision (paragraph 1). The right yields to exceptions provided under Union or national law (paragraph 2) and applies only where Union law grants no equivalent right (paragraph 3). Deployers in credit, employment, education and public services should build explanation workflows.

Recitals 171

Article 87: Reporting of Infringements and Protection of Reporting Persons

applies 2 August 2026Everyoneenforcement

Directive (EU) 2019/1937, the whistleblower protection directive, applies to the reporting of infringements of the Regulation and to the protection of persons reporting them. Employees and contractors of providers and deployers who report breaches of the AI Act therefore enjoy the same protection against retaliation as for other Union law, and organisations should extend their internal reporting channels and non-retaliation policies to cover AI Act infringements.

Recitals 172

Article 88: Enforcement of the Obligations of Providers of General-Purpose AI Models

applies 2 August 2026CommissionGPAI providersAuthoritiesgpaienforcement

The Commission holds exclusive powers to supervise and enforce Chapter V, the obligations of providers of general-purpose AI models, with the procedural safeguards of Article 94, and entrusts implementation to the AI Office (paragraph 1). Without prejudice to Article 75(3), market surveillance authorities may ask the Commission to use these powers where necessary and proportionate to their own tasks (paragraph 2). Providers of general-purpose AI models deal with the AI Office as their regulator, not with national authorities.

Recitals 162

Article 89: Monitoring Actions

applies 2 August 2026CommissionGPAI providersProvidersgpaienforcement

The AI Office may take any necessary action to monitor the effective implementation and compliance of general-purpose AI model providers, including adherence to approved codes of practice (paragraph 1). Downstream providers may lodge a substantiated complaint, giving the model provider's contact point, a description of the facts, the provisions concerned and the reasons for suspecting an infringement, plus any other relevant information (paragraph 2). Downstream providers denied the documentation owed under Article 53 should use this route rather than a national complaint.

Recitals 164

Article 90: Alerts of Systemic Risks by the Scientific Panel

applies 2 August 2026CommissionGPAI providersInstitutionalgpaigovernance

The scientific panel may send a qualified alert to the AI Office where it suspects that a general-purpose AI model poses a concrete identifiable risk at Union level or meets the systemic-risk conditions of Article 51 (paragraph 1). The Commission, through the AI Office and after informing the Board, may then use the powers in Articles 91 to 94 and keeps the Board informed (paragraph 2). The alert must be reasoned and name the provider, describe the facts and give the panel's grounds (paragraph 3). Model providers should expect enforcement to start from independent scientific scrutiny, not only from complaints.

Recitals 163

Article 91: Power to Request Documentation and Information

applies 2 August 2026CommissionGPAI providersgpaienforcement

The Commission may require a general-purpose AI model provider to supply the documentation drawn up under Articles 53 and 55 or any other information needed to assess compliance (paragraph 1), after an optional structured dialogue with the AI Office (paragraph 2), and also at the substantiated request of the scientific panel (paragraph 3). Requests state the legal basis, purpose, the information required, a deadline and the Article 101 fines for incorrect, incomplete or misleading answers (paragraph 4). The provider or its representative answers; lawyers may act but the provider remains fully responsible (paragraph 5). Keep Article 53 and 55 documentation ready to hand over on demand.

Recitals 164

Article 92: Power to Conduct Evaluations

applies 2 August 2026CommissionGPAI providersgpaienforcement

The AI Office, after consulting the Board, may evaluate a general-purpose AI model to assess compliance where Article 91 information is insufficient, or to investigate Union-level systemic risks of a model with systemic risk, in particular after a qualified alert under Article 90(1)(a) (paragraph 1). Independent experts, including scientific panel members, may conduct the evaluation (paragraph 2), and the Commission may demand access to the model through APIs or other technical means, including source code (paragraph 3), with requests citing Article 101 fines (paragraph 4). Implementing acts set the arrangements (paragraph 6); a structured dialogue on internal testing may precede access (paragraph 7). Providers should prepare secure evaluator access.

Recitals 164

Article 93: Power to Request Measures

applies 2 August 2026CommissionGPAI providersgpaienforcement

Where warranted, the Commission may request a general-purpose AI model provider to take measures to comply with Articles 53 and 54, to implement mitigation measures where an Article 92 evaluation raises serious concern of a systemic risk at Union level, or to restrict, withdraw or recall the model from the market (paragraph 1). A structured dialogue with the AI Office may come first (paragraph 2), and commitments offered by the provider during that dialogue can be made binding by Commission decision, closing the matter (paragraph 3). Providers of models with systemic risk should keep mitigation options ready to offer as commitments.

Recitals 164

Article 94: Procedural Rights of Economic Operators of the General-Purpose AI Model

applies 2 August 2026GPAI providersCommissiongpaienforcement

Article 18 of Regulation (EU) 2019/1020 applies mutatis mutandis to providers of general-purpose AI models, giving them the right to be heard, reasoned decisions and information on remedies before the Commission adopts measures under Section 5, without prejudice to more specific procedural rights elsewhere in the Regulation. Providers facing AI Office action should invoke these rights at the preliminary findings stage under Article 101(2) and keep a record of every exchange.

Recitals 164

Chapter X: Codes of Conduct and Guidelines2 provisions

Article 95: Codes of Conduct for Voluntary Application of Specific Requirements

applies 2 August 2026amended by 2026/1744CommissionProvidersDeployersothergovernance

The AI Office and the Member States encourage voluntary codes of conduct, including governance mechanisms, that apply some or all of the Chapter III, Section 2 requirements to AI systems that are not high-risk (paragraph 1), and codes with clear objectives and key performance indicators on ethics guidelines, environmental sustainability, AI literacy, inclusive design and vulnerable persons (paragraph 2). Individual providers or deployers, their organisations or others may draw up codes covering one or several systems (paragraph 3), and the specific needs of SMEs, start-ups and SMCs are taken into account (paragraph 4). Voluntary adherence is a low-cost way to evidence good practice for non-high-risk systems.

Paragraph 4 is amended to add SMCs (small mid-caps) to the SMEs and start-ups whose interests are considered when codes are drawn up.

Recitals 165, 166

Article 96: Guidelines from the Commission on the Implementation of this Regulation

applies 2 August 2026amended by 2026/1744CommissionEveryonegovernanceother

The Commission develops guidelines on practical implementation covering the Articles 8 to 15 requirements and Articles 25 and 26 obligations, the Article 5 prohibitions, substantial modification, the Article 50 transparency obligations, the interplay with Annex I and other Union law, the Article 3(1) definition of an AI system, and, by 1 August 2027, the complementarity and proportionality mechanisms of Articles 8(2), 9(10) and 17(3) (paragraph 1). It consults the Board and weighs the needs of SMEs, start-ups, SMCs, local authorities and affected sectors, and updates guidelines on request or on its own initiative (paragraph 2). Track these guidelines; they shape how authorities apply the Act.

New point (g) in paragraph 1 requires guidelines on the complementarity and proportionality mechanisms of Articles 8(2), 9(10) and 17(3) by 1 August 2027, and the final sentence is amended to add Board consultation and SMCs.

Chapter XI: Delegation of Power and Committee Procedure2 provisions

Article 97: Exercise of the Delegation

applies 2 August 2026amended by 2026/1744CommissionInstitutionalgovernanceother

The Commission's power to adopt delegated acts runs for five years from 1 August 2024, and for the delegations under Articles 2(13) and 30(2) from 27 July 2026, with tacit extension unless the European Parliament or the Council objects, the Commission reporting nine months before expiry (paragraph 2). Either institution may revoke a delegation (paragraph 3), and a delegated act enters into force only if neither objects within three months of notification, extendable by three months (paragraph 6). It concerns the Union legislator and the Commission; operators should watch delegated acts because they can change Annex III and the thresholds in Chapter V.

Paragraphs 2, 3 and 6 are amended to cover the new delegations under Articles 2(13) and 30(2), whose five-year period runs from 27 July 2026.

Recitals 173

Article 98: Committee Procedure

applies 2 August 2026CommissionInstitutionalgovernance

The Commission is assisted by a committee within the meaning of Regulation (EU) No 182/2011 (paragraph 1), and the examination procedure of Article 5 of that Regulation applies wherever the Act refers to Article 98(2) (paragraph 2). It concerns the Commission and Member State representatives; practitioners should note that implementing acts on templates, common specifications and evaluation arrangements all pass through this procedure.

Recitals 175

Chapter XII: Penalties3 provisions

Article 99: Penalties

applies 2 August 2025amended by 2026/1744AuthoritiesProvidersDeployerspenalties

Member States lay down penalties, including fines, warnings and non-monetary measures, that are effective, proportionate and dissuasive and reflect the interests of SMEs, start-ups and SMCs (paragraph 1). Breaches of Article 5 draw fines up to EUR 35 000 000 or 7 % of worldwide annual turnover, whichever is higher (paragraph 3); breaches of provider, representative, importer, distributor, deployer, notified body and Article 50 obligations, and of Article 25(2) and (4), up to EUR 15 000 000 or 3 % (paragraph 4); incorrect or misleading information up to EUR 7 500 000 or 1 % (paragraph 5). For SMEs and SMCs the lower amount applies (paragraphs 6 and 6a).

New point (da) in paragraph 4 brings obligations under Article 25(2) and (4) into the EUR 15 000 000 or 3 % tier, and new paragraph 6a caps fines on SMCs at the lower of the two amounts.

Recitals 168

Article 100: Administrative Fines on Union Institutions, Bodies, Offices and Agencies

applies 2 August 2025AuthoritiesInstitutionalpenalties

The European Data Protection Supervisor may fine Union institutions, bodies, offices and agencies, weighing the nature and gravity of the infringement, responsibility, mitigation, cooperation, previous infringements, how it came to light and the institution's annual budget (paragraph 1). Article 5 breaches draw fines up to EUR 1 500 000 (paragraph 2); other breaches up to EUR 750 000 (paragraph 3). The institution is heard first and has full rights of defence and file access (paragraphs 4 and 5), fines go to the Union budget (paragraph 6) and the Supervisor reports annually to the Commission (paragraph 7). It concerns Union bodies deploying AI, not private operators.

Recitals 168

Article 101: Fines for Providers of General-Purpose AI Models

applies 2 August 2025CommissionGPAI providerspenaltiesgpai

The Commission may fine providers of general-purpose AI models up to 3 % of worldwide annual turnover or EUR 15 000 000, whichever is higher, for intentional or negligent breaches of Chapter V, failure to answer Article 91 requests or supplying incorrect information, non-compliance with Article 93 measures or refusing access for Article 92 evaluations (paragraph 1). Preliminary findings and a right to reply precede any decision (paragraph 2), fines must be effective, proportionate and dissuasive (paragraph 3), and the Court of Justice may cancel, reduce or increase them (paragraph 5). Article 113(b) excludes Article 101 from the 2 August 2025 date, so fining applies from 2 August 2026.

Recitals 169

Chapter XIII: Final Provisions12 provisions

Article 102: Amendment to Regulation (EC) No 300/2008

applies 27 July 2026CommissionInstitutionalother

Regulation (EC) No 300/2008 on civil aviation security gains a subparagraph in Article 4(3) requiring that measures on technical specifications and on approval and use of security equipment involving AI systems take account of the Chapter III, Section 2 requirements. It concerns the Commission when legislating in aviation security and providers of such equipment, who should expect the AI Act requirements to flow into the sectoral rules rather than apply through the AI Act's own conformity route.

Recitals 49

Article 103: Amendment to Regulation (EU) No 167/2013

applies 27 July 2026CommissionInstitutionalother

Regulation (EU) No 167/2013 on agricultural and forestry vehicles gains a subparagraph in Article 17(5) requiring the Commission, when adopting delegated acts on AI systems that are safety components under the AI Act, to take account of the Chapter III, Section 2 requirements. It concerns the Commission and manufacturers of such vehicles, whose AI safety components follow the sectoral type-approval route under Annex I, Section B.

Recitals 49

Article 104: Amendment to Regulation (EU) No 168/2013

applies 27 July 2026CommissionInstitutionalother

Regulation (EU) No 168/2013 on two- or three-wheel vehicles and quadricycles gains a subparagraph in Article 22(5) requiring the Commission, when adopting delegated acts on AI systems that are safety components under the AI Act, to take account of the Chapter III, Section 2 requirements. It concerns the Commission and manufacturers of such vehicles, whose AI safety components follow the sectoral type-approval route under Annex I, Section B.

Recitals 49

Article 105: Amendment to Directive 2014/90/EU

applies 27 July 2026CommissionInstitutionalother

Directive 2014/90/EU on marine equipment gains a new paragraph 5 in Article 8 requiring the Commission, when acting under paragraph 1 and when adopting technical specifications and testing standards under paragraphs 2 and 3 for AI systems that are safety components under the AI Act, to take account of the Chapter III, Section 2 requirements. It concerns the Commission and marine equipment manufacturers, whose AI safety components follow the sectoral route under Annex I, Section B.

Recitals 49

Article 106: Amendment to Directive (EU) 2016/797

applies 27 July 2026CommissionInstitutionalother

Directive (EU) 2016/797 on rail interoperability gains a new paragraph 12 in Article 5 requiring the Commission, when adopting delegated or implementing acts on AI systems that are safety components under the AI Act, to take account of the Chapter III, Section 2 requirements. It concerns the Commission and rail subsystem manufacturers, whose AI safety components follow the sectoral route under Annex I, Section B.

Recitals 49

Article 107: Amendment to Regulation (EU) 2018/858

applies 27 July 2026CommissionInstitutionalother

Regulation (EU) 2018/858 on type-approval of motor vehicles gains a new paragraph 4 in Article 5 requiring the Commission, when adopting delegated acts on AI systems that are safety components under the AI Act, to take account of the Chapter III, Section 2 requirements. It concerns the Commission and vehicle manufacturers, whose AI safety components follow the sectoral type-approval route under Annex I, Section B rather than the AI Act's own conformity assessment.

Recitals 49

Article 108: Amendments to Regulation (EU) 2018/1139

applies 27 July 2026CommissionInstitutionalother

Regulation (EU) 2018/1139 on civil aviation safety is amended in six places, Articles 17, 19, 43, 47, 57 and 58, so that implementing and delegated acts on AI systems that are safety components under the AI Act take account of the Chapter III, Section 2 requirements. It concerns the Commission and aviation product and equipment manufacturers, whose AI safety components follow the sectoral certification route under Annex I, Section B.

Recitals 49

Article 109: Amendment to Regulation (EU) 2019/2144

applies 27 July 2026CommissionInstitutionalother

Regulation (EU) 2019/2144 on general vehicle safety gains a new paragraph 3 in Article 11 requiring the Commission, when adopting implementing acts on AI systems that are safety components under the AI Act, to take account of the Chapter III, Section 2 requirements. It concerns the Commission and vehicle manufacturers, whose AI safety components, including automated driving functions, follow the sectoral route under Annex I, Section B.

Recitals 49

Article 110: Amendment to Directive (EU) 2020/1828

applies 27 July 2026EveryoneProvidersDeployersenforcementother

Annex I to Directive (EU) 2020/1828 on representative actions for the protection of consumers' collective interests gains a reference to the AI Act. Qualified entities can therefore bring collective redress actions against providers and deployers for infringements of the Regulation that harm consumers, so operators facing consumers should factor class-style litigation into their AI Act risk assessment.

Recitals 49

Article 111: AI Systems Already Placed on the Market or Put into Service and General-Purpose AI Models Already Placed on the Market

applies in force 1 August 2024amended by 2026/1744ProvidersDeployersGPAI providersscopetransparencygpai

AI systems that are components of the large-scale IT systems in Annex X placed on the market before 2 August 2027 must comply by 31 December 2030 (paragraph 1). Other high-risk AI systems on the market before the applicable Chapter III date fall under the Regulation only if their design changes significantly afterwards, but systems intended for public authorities must comply by 2 August 2030 (paragraph 2). General-purpose AI models on the market before 2 August 2025 comply by 2 August 2027 (paragraph 3). Providers of systems generating synthetic audio, image, video or text marketed before 2 August 2026 must meet Article 50(2) by 2 December 2026 (paragraph 4).

Paragraph 2 is amended to key the grandfathering of existing high-risk systems to the new Chapter III application dates in Article 113, and new paragraph 4 gives providers of synthetic content generators already on the market before 2 August 2026 until 2 December 2026 to comply with Article 50(2).

Recitals 177

Article 112: Evaluation and Review

applies in force 1 August 2024CommissionInstitutionalgovernanceother

The Commission assesses annually whether Annex III and the Article 5 prohibitions need amendment (paragraph 1); by 2 August 2028 and every four years it reviews the Annex III headings, the Article 50 transparency list and the governance system (paragraph 2), with a broader enforcement evaluation by 2 August 2029 (paragraph 3). Further reports by 2 August 2028 cover the AI Office's powers and resources (paragraph 5), standardisation for energy-efficient general-purpose models (paragraph 6) and, every three years, voluntary codes of conduct (paragraph 7). The AI Office builds a risk-evaluation methodology for Annex III changes (paragraph 11); a final enforcement assessment is due by 2 August 2031 (paragraph 13).

Recitals 174

Article 113: Entry into Force and Application

applies in force 1 August 2024amended by 2026/1744EveryoneInstitutionalscopeother

The Regulation entered into force on 1 August 2024 and applies in general from 2 August 2026. Chapters I and II applied from 2 February 2025, except Article 5(1), points (ba) and (bb), and Article 5(1a) and (1b), which apply from 2 December 2026 (point (a)); Chapter III, Section 4, Chapters V, VII and XII and Article 78 applied from 2 August 2025, except Article 101 (point (b)). Chapter III, Sections 1 to 3, other than Article 6(5), apply from 2 December 2027 for Annex III high-risk systems and from 2 August 2028 for Annex I systems (point (c)); Articles 102 to 110 apply from 27 July 2026 (point (d)).

Point (a) is amended to defer the new Article 5 prohibitions to 2 December 2026, point (c) is amended and split so that Annex III high-risk rules apply from 2 December 2027 instead of 2 August 2026 and Annex I high-risk rules from 2 August 2028, and new point (d) applies Articles 102 to 110 from 27 July 2026.

Recitals 178, 179

Annexes14 provisions

Annex I: List of Union Harmonisation Legislation

applies 2 August 2028amended by 2026/1744ProvidersNotified bodieshigh risk classificationconformityscope

Annex I lists the product legislation that makes an AI safety component, or an AI system that is itself a product, high-risk under Article 6(1). Section A holds New Legislative Framework acts (toys, recreational craft, lifts, equipment for explosive atmospheres, radio equipment, pressure equipment, cableways, personal protective equipment, gas appliances, medical devices and in vitro diagnostics), where the AI Act requirements are checked inside the sectoral conformity assessment. Section B holds aviation, vehicles, marine equipment and rail, where only Article 6(1) and Articles 102 to 109 bite. Providers of regulated products map every AI component against the list; the Annex I obligations apply from 2 August 2028.

The amendment deleted point 1, the Machinery Directive 2006/42/EC, and added point 21, the Machinery Regulation (EU) 2023/1230, in Section B.

Recitals 33, 47, 49, 50, 51

Annex II: List of Criminal Offences Referred to in Article 5(1), First Subparagraph, Point (h)(iii)

applies 2 February 2025DeployersAuthoritiesprohibitions

Annex II lists the 16 categories of serious criminal offence (terrorism, trafficking in human beings, child sexual exploitation, drug and arms trafficking, murder and grievous bodily injury, organ trade, nuclear material, kidnapping, International Criminal Court crimes, hijacking, rape, environmental crime, organised or armed robbery, sabotage and participation in a criminal organisation) that unlock the third exception to the ban on real-time remote biometric identification in Article 5(1)(h)(iii). The exception covers only locating or identifying a suspect of one of these offences where the offence carries a custodial sentence of at least four years in the Member State concerned. Law enforcement deployers check the offence against the list before any use.

Annex III: High-Risk AI Systems Referred to in Article 6(2)

applies 2 December 2027ProvidersDeployersCommissionhigh risk classificationscope

Annex III lists the stand-alone use cases that are high-risk under Article 6(2), in eight areas: biometrics (remote identification, categorisation by sensitive attributes, emotion recognition), safety components of critical infrastructure, education and vocational training, employment and worker management, access to essential services (benefits, credit scoring, life and health insurance pricing, emergency triage), law enforcement, migration and border control, and administration of justice and elections. Providers classify against the list, then test the Article 6(3) filter for systems that do not materially influence the outcome; deployers of listed systems pick up Articles 26 and 27. The Commission amends the list under Article 7. Annex III obligations apply from 2 December 2027.

Recitals 48, 52, 54, 55, 56, 57, 58, 59, 60, 61, 62, 63, 159

Annex IV: Technical Documentation Referred to in Article 11(1)

applies 2 December 2027 (Annex III) or 2 August 2028 (Annex I)ProvidersNotified bodiesprovider dutiesconformitydata

Annex IV sets the minimum content of the technical documentation a provider of a high-risk AI system draws up under Article 11(1) before placing it on the market. Its nine points cover a general description (intended purpose, versions, hardware, interfaces, instructions for use), a detailed description of development (methods, design choices, architecture, data provenance, human oversight assessment, pre-determined changes, validation and testing metrics, cybersecurity), monitoring and control information, performance metrics, the Article 9 risk management system, lifecycle changes, harmonised standards applied, the Article 47 declaration of conformity and the Article 72 post-market monitoring plan. Providers structure their evidence file around these headings; SMEs can use the Commission's simplified form.

Annex V: EU Declaration of Conformity

applies 2 December 2027 (Annex III) or 2 August 2028 (Annex I)Providersconformityprovider duties

Annex V prescribes the eight elements of the EU declaration of conformity a provider signs under Article 47: identification of the system (name, type, traceability references), name and address of the provider or authorised representative, a statement that it is issued under the provider's sole responsibility, a statement of conformity with the Regulation and other Union law requiring a declaration, where personal data is processed a statement of compliance with Regulations (EU) 2016/679 and (EU) 2018/1725 and Directive (EU) 2016/680, references to harmonised standards or common specifications, notified body details and certificate where applicable, and place, date, signatory and signature. Providers update it after changes.

Annex VI: Conformity Assessment Procedure Based on Internal Control

applies 2 December 2027 (Annex III) or 2 August 2028 (Annex I)Providersconformityprovider duties

Annex VI defines the self-assessment route that Article 43(2) assigns to most Annex III high-risk systems and that Article 43(1) allows for biometric systems where harmonised standards are applied in full. Under points 2 to 4 the provider verifies that its quality management system meets Article 17, examines the technical documentation to confirm the system meets the essential requirements in Chapter III, Section 2, and verifies that the design and development process and the Article 72 post-market monitoring are consistent with that documentation. No notified body is involved, so the provider's own records carry the burden of proof; each check needs dated evidence before the Article 47 declaration is signed.

Annex VII: Conformity Based on an Assessment of the Quality Management System and an Assessment of the Technical Documentation

applies 2 December 2027 (Annex III) or 2 August 2028 (Annex I)ProvidersNotified bodiesconformityprovider duties

Annex VII is the third-party route under Article 43(1), mandatory for Annex III biometric systems where harmonised standards are not fully applied. The provider applies to a single notified body with its Article 17 quality management system documentation and the technical documentation (point 2). The notified body audits the quality management system, examines the technical documentation, may demand tests and gains access to training, validation and testing data sets and, as a last resort on reasoned request, to trained models (points 4.3 to 4.5). It issues a Union technical documentation assessment certificate, assesses every change affecting compliance and runs periodic surveillance audits (points 4.6, 4.7 and 5).

Annex VIII: Information to be Submitted upon the Registration of High-Risk AI Systems in Accordance with Article 49

applies 2 December 2027 (Annex III) or 2 August 2028 (Annex I)amended by 2026/1744ProvidersDeployersCommissionregistrationprovider dutiesdeployer duties

Annex VIII fixes the data entered in the EU database under Article 49. Section A, for providers of Annex III high-risk systems under Article 49(1), lists 13 items: provider details, trade name and identifiers, intended purpose, input and operating logic, market status, notified body certificate, Member States of availability, the declaration of conformity, electronic instructions for use. Section B, for providers relying on the Article 6(3) exemption under Article 49(2), lists identity, trade name, intended purpose, the Article 6(3) condition invoked and market status. Section C, for public authority deployers under Article 49(3), adds the provider's entry and impact assessment summaries.

The amendment deleted Section B points 7 and 9, so providers relying on Article 6(3) no longer register a summary of the grounds for non-high-risk classification or the Member States where the system is available.

Annex IX: Information to be Submitted upon the Registration of High-Risk AI Systems Listed in Annex III in Relation to Testing in Real World Conditions in Accordance with Article 60

applies 2 August 2026ProvidersDeployersregistrationsandboxes

Annex IX lists the five items a provider or prospective provider registers in the EU database before testing an Annex III high-risk system in real world conditions outside a sandbox under Article 60(4)(c): a Union-wide unique identification number for the test, the name and contact details of the provider or prospective provider and of the deployers involved, a brief description of the system and its intended purpose, a summary of the main characteristics of the testing plan, and information on any suspension or termination. The entry is kept up to date throughout the test, so every change to the plan is logged as it happens.

Annex X: Union Legislative Acts on Large-Scale IT Systems in the Area of Freedom, Security and Justice

applies in force 1 August 2024AuthoritiesCommissionInstitutionalscopeother

Annex X names the seven large-scale EU information systems whose legal bases trigger the transitional rule in Article 111(1): the Schengen Information System (Regulations (EU) 2018/1860, 2018/1861 and 2018/1862), the Visa Information System (Regulations (EU) 2021/1133 and 2021/1134), Eurodac (Regulation (EU) 2024/1358), the Entry/Exit System (Regulation (EU) 2017/2226), ETIAS (Regulations (EU) 2018/1240 and 2018/1241), ECRIS-TCN (Regulation (EU) 2019/816) and interoperability (Regulations (EU) 2019/817 and 2019/818). AI components of these systems placed on the market or put into service before 2 August 2027 must comply by 31 December 2030, except that the Article 5 prohibitions apply without delay. The list concerns the Commission and the Member State authorities operating those systems.

Annex XI: Technical Documentation Referred to in Article 53(1), Point (a): Technical Documentation for Providers of General-Purpose AI Models

applies 2 August 2025GPAI providersAuthoritiesgpaiprovider dutiesdata

Annex XI sets the minimum technical documentation every provider of a general-purpose AI model keeps under Article 53(1)(a) and supplies to the AI Office on request, scaled to the size and risk profile of the model. Section 1 requires a general description (intended tasks and integration types, acceptable use policies, release date and distribution channels, architecture and parameter count, modalities, licence) plus development details: integration means, design and training methodology, the type, provenance, curation, scope and bias-detection approach for training data, compute and training time, and known or estimated energy consumption. Section 2 adds, for systemic-risk models, evaluation results, adversarial testing and system architecture.

Recitals 101

Annex XII: Transparency Information Referred to in Article 53(1), Point (b): Technical Documentation for Providers of General-Purpose AI Models to Downstream Providers That Integrate the Model into Their AI System

applies 2 August 2025GPAI providersProvidersgpaitransparency

Annex XII lists what a general-purpose AI model provider must hand to downstream providers under Article 53(1)(b) so they can understand the model's capabilities and limitations and meet their own obligations. Point 1 covers the model: intended tasks and compatible system types, acceptable use policies, release date and distribution channels, hardware and software interaction, software versions, architecture and parameter count, modalities and formats, and licence. Point 2 covers the elements and development process: the technical means and instructions needed for integration, input and output modalities and maximum sizes, and the type, provenance and curation methodologies of training, testing and validation data. Downstream providers request this pack before integrating a model.

Recitals 101

Annex XIII: Criteria for the Designation of General-Purpose AI Models with Systemic Risk Referred to in Article 51

applies 2 August 2025CommissionGPAI providersgpaigovernance

Annex XIII gives the Commission seven criteria for deciding under Article 51(1)(a) whether a general-purpose AI model has high-impact capabilities equivalent to those presumed above the 10^25 FLOPs threshold in Article 51(2): (a) number of parameters, (b) data set quality or size in tokens, (c) training compute in floating point operations or proxies, (d) input and output modalities, (e) benchmarks of capability, adaptability, autonomy, scalability and tool access, (f) market impact, presumed high at 10 000 or more registered business users, and (g) registered end users. GPAI providers track these indicators to anticipate or contest a designation under Article 52.

Recitals 111

Annex XIV: The list of codes, categories and corresponding types of AI systems for the purpose of the notification procedure referred to in Article 30 specifying the scope of the designation as notified bodies

applies 2 August 2026amended by 2026/1744Notified bodiesAuthoritiesconformitystandards

Annex XIV supplies the codes that fix the scope of a notified body's designation under Article 30: a body assesses only the types of AI system in its designation (section 1). Section 2 lists product and use categories: AIP 0102 to AIP 0112 for Annex I Section A products in points 2 to 12, and AIB 0201 to AIB 0203 for remote biometric identification, biometric categorisation and emotion recognition. Section 3 lists technology codes: AIH 0101 for symbolic, expert and knowledge-based systems, AIH 0201 to AIH 0205 for machine learning on structured, signal, text and image data, AIH 0301 for generative AI systems including those built on general-purpose AI models, and AIH 0401 for emerging technologies including agentic AI. Article 29 applicants must use these codes (section 4).

Inserted by Regulation (EU) 2026/1744: it adds a standard code list (AIP, AIB and AIH codes) that notified bodies must use to define the product, biometric and technology scope of their designation.

Part 2: guidance and implementation

The Regulation and its amendment3 documents

Commission Implementing Regulation (EU) 2025/454 on the scientific panel of independent experts

5 March 2025 · European Commissiondelegated or implementing actArt 68Art 90governancegpainot fetched

Binding implementing act adopted 5 March 2025 under Article 68(1), laying down rules for the establishment and functioning of the scientific panel: selection of experts through an open call, independence and conflict-of-interest declarations, the 24-month renewable term, the chair and vice-chair chosen from among members, working arrangements with the AI Office and the procedure for qualified alerts to the AI Office under Article 90 when a GPAI model presents a concrete identifiable Union-level risk or should be classified as posing systemic risk. Providers of GPAI models should understand that a panel alert can initiate a request for information, an evaluation or a classification decision.

Regulation (EU) 2024/1689 laying down harmonised rules on artificial intelligence (AI Act)

13 June 2024 · European Parliament and CouncilregulationArt 1-113Annex IAnnex IIIAnnex IVscopehigh risk classificationgovernance

The founding text, adopted 13 June 2024, published in the Official Journal on 12 July 2024 and in force since 1 August 2024. It binds providers, deployers, importers, distributors and authorised representatives of AI systems and providers of general-purpose AI models across 113 articles, 13 chapters, 180 recitals and its annexes. Read it in the consolidated form as amended by Regulation (EU) 2026/1744, which rewrote 42 articles and 3 annexes and shifted the high-risk application dates to 2 December 2027 (Annex III) and 2 August 2028 (Annex I). Every other document in this corpus interprets or implements it.

Regulation (EU) 2026/1744 amending the AI Act (Digital Omnibus on AI)

8 July 2026 · European Parliament and CouncilregulationArt 4-6Art 50Art 74-75Art 111-113high risk classificationprohibitionsgovernance

Binding amending regulation adopted 8 July 2026, published 24 July 2026, in force 27 July 2026. It moves high-risk application to 2 December 2027 for Annex III and 2 August 2028 for Annex I, rewrites Article 4 on AI literacy, adds Article 4a allowing special-category data for bias detection, bans non-consensual intimate deepfakes and child sexual abuse material in Article 5(1)(ba) and (bb) from 2 December 2026, extends SME relief to small mid-caps and gives the AI Office exclusive competence over GPAI-based systems and AI in very large platforms. Pre-existing generative systems get four months from 2 August 2026 for Article 50(2) marking. Re-baseline every plan on it.

Commission guidelines and Q&As10 documents

AI Act Service Desk FAQ category on the Digital Omnibus on AI

27 July 2026 · European Commission (AI Office)qaArt 4Art 49Art 75Art 113governancescope

Dedicated FAQ set that the Commission points to from every explorer page carrying the notice that its text has not yet been updated for Regulation (EU) 2026/1744. It explains why the Act was amended after stakeholder consultations throughout 2025, the delay of up to 16 months for Annex III and 12 months for Annex I systems, the extension of simplified compliance from SMEs to small mid-caps reaching an estimated 8,250 additional companies, the reduced registration burden, the AI Office's centralised oversight of GPAI-based systems and AI on very large platforms, special-category data for bias detection, expanded sandboxes and an EU-level sandbox from 2028. Non-binding; check answers against the enacted text.

AI literacy questions and answers (updated for the Digital Omnibus)

27 July 2026 · European CommissionqaArt 4Art 62(3)literacydeployer duties

Non-binding Q&A updated 27 July 2026 to reflect the rewritten Article 4. Providers and deployers must take measures to support the AI literacy of staff and other persons operating AI systems, taking account of their knowledge, experience, education and context; the former 'sufficient level' threshold is gone and no single approach is mandated. The Commission and Member States support compliance and publish practical examples on the Single Information Platform, and the AI Board adopts recommendations under Article 4(3). Article 4 applied from 2 February 2025 and national market surveillance authorities supervise it from 2 August 2026 with proportionate, case-by-case penalties, so document your measures and map them to roles.

Commission Guidelines on prohibited artificial intelligence practices

4 February 2025 · European Commissioncommission guidelinesArt 5prohibitions

Non-binding guidelines approved by the College on 4 February 2025, two days after the Article 5 prohibitions began to apply on 2 February 2025. They set out the Commission's reading of each prohibited practice, including harmful manipulation, exploitation of vulnerabilities, social scoring, predictive policing, untargeted facial scraping, emotion recognition at work and in education, biometric categorisation and real-time remote biometric identification, with exceptions and the interplay with other Union law. Authoritative interpretation stays with the Court of Justice. They predate the Omnibus, so read the new points (ba) and (bb) on intimate deepfakes and CSAM directly from Regulation (EU) 2026/1744.

Commission Guidelines on the definition of an AI system

6 February 2025 · European Commissioncommission guidelinesArt 3(1)Art 96scope

Non-binding guidelines published 6 February 2025 explaining how to apply the Article 3(1) definition of an AI system, which took effect with the first provisions on 2 February 2025. They walk through the definitional elements (machine-based system, autonomy, adaptiveness, objectives, inference, outputs, influence on environments) and distinguish systems that fall outside the Act, such as basic statistical or rule-based processing. The Commission states they will evolve and be updated. Use them as the first gate in any inventory: if software is not an AI system, the Act does not apply.

Commission Guidelines on the scope of obligations for providers of general-purpose AI models

18 July 2025 · European Commissioncommission guidelinesArt 3(63)Art 51-55Art 111(3)gpaiprovider duties

Non-binding guidelines approved 18 July 2025 and last updated 28 April 2026, setting out how the Commission will enforce Chapter V. They give technical criteria for when a model is general-purpose, explain the systemic-risk notification duty to the AI Office, the conditions of the open-source exemption, and the rule that only downstream actors making significant modifications become providers. Obligations applied from 2 August 2025, the Commission's fining powers started 2 August 2026, and models placed on the market before 2 August 2025 must comply by 2 August 2027. Read alongside the GPAI Code of Practice.

Commission Guidelines on transparency obligations for providers and deployers of certain AI systems (Article 50)

20 July 2026 · European Commissioncommission guidelinesArt 50Art 111(4)transparencyprovider dutiesdeployer duties

Final non-binding guidelines published 20 July 2026, following a draft of 8 May 2026, addressed to competent authorities, providers and deployers so that Article 50 is applied consistently, proportionately and uniformly from 2 August 2026. They cover disclosure when a person interacts with an AI system, machine-readable marking of synthetic audio, image, video and text, information duties for emotion recognition and biometric categorisation, and labelling of deepfakes and public-interest text, with the exceptions in Article 50. Providers of generative systems already on the market before 2 August 2026 have until 2 December 2026 for marking under the Omnibus transition. Pair with the code and the EU icons.

Draft Commission Guidelines on the classification of high-risk AI systems

19 May 2026 · European Commissioncommission guidelinesdraftArt 6Annex IAnnex IIIArt 25high risk classification

Draft guidelines published 19 May 2026 under Article 6(5), which required them by 2 February 2026, and opened to targeted stakeholder consultation with a last update on 23 July 2026. They treat the two classification routes separately: Article 6(1) safety components of Annex I products subject to third-party conformity assessment, and Article 6(2) Annex III use cases, with practical examples of systems that are and are not high-risk. The AI Act Service Desk hosts an accompanying guideline explorer. They remain non-binding and draft; expect a final version before the Annex III application date of 2 December 2027 and reconcile them with the Omnibus additions to Article 6(1a) to (1c).

MDCG 2025-6: Interplay between the MDR/IVDR and the AI Act

19 June 2025 · Medical Device Coordination Group with the AI BoardqaArt 6(1)Art 8Art 43Annex Ihigh risk classificationconformitynot fetched

Joint question-and-answer guidance published in June 2025 by the Medical Device Coordination Group and the AI Board's dedicated subgroup, non-binding but the reference for AI in medical devices. It confirms that an AI system that is a device or a safety component of a device requiring notified body assessment under the MDR or IVDR is high-risk under Article 6(1), and explains how the AI Act requirements fold into a single conformity assessment, technical documentation and quality management system under Article 8, how notified bodies are designated for both frameworks, and how post-market surveillance and incident reporting are coordinated. Medical device manufacturers now have until 2 August 2028 under the Omnibus.

Navigating the AI Act: questions and answers

7 August 2026 · European CommissionqaArt 6Art 51Art 99Art 113scopepenaltiesgovernance

General non-binding Q&A updated 7 August 2026 covering scope and the risk-based approach, high-risk classification and obligations, GPAI documentation and the 10^25 FLOP systemic-risk presumption, the two-tier governance of AI Office and national authorities, penalties of up to EUR 35 million or 7 percent for prohibited practices, EUR 15 million or 3 percent for other breaches and EUR 7.5 million or 1 percent for misleading information, and the post-Omnibus dates of 2 December 2027 and 2 August 2028. It reports more than 3,000 organisations interested in the AI Pact and over 230 pledge signatories as of December 2025. A sound orientation text for non-specialists.

Questions and answers on general-purpose AI models in the AI Act

9 September 2025 · European CommissionqaArt 51-55Art 91-93Art 101gpaienforcement

Non-binding Q&A last updated 9 September 2025 that condenses the GPAI guidelines. It gives the indicative criterion of training compute above 10^23 FLOP with generative capability, the systemic-risk presumption at 10^25 FLOP under Article 51(1)(a), the one-third-of-compute rule under which a modifier becomes a new provider, and the open-source exemption from Article 53(1)(a) and (b) that never covers systemic-risk models. It explains AI Office powers to request information, evaluate models and order recalls under Articles 91 to 93, and fines of up to 3 percent of worldwide turnover or EUR 15 million under Article 101. Use it as the quick reference before the full guidelines.

Codes of practice and templates5 documents

Code of Practice on transparency of AI-generated content (marking and labelling)

10 June 2026 · European Commission (AI Office), drafted by independent expertscode of practicevoluntaryArt 50(2)Art 50(4)Art 50(5)transparencyprovider dutiesdeployer duties

Voluntary code finalised 10 June 2026 after drafts of 17 December 2025 and 3 March 2026, drawn up by two working groups after a kick-off plenary on 5 November 2025. Section 1 binds signatory providers of generative systems to mark outputs in machine-readable form and enable detection under Article 50(2) with solutions that are effective, interoperable, robust and reliable; Section 2 binds deployers to disclose deepfakes and AI-generated text on matters of public interest under Article 50(4). By the end of July 2026 around 190 organisations had signed, 95 under Section 1 and 192 under Section 2. Obligations applied 2 August 2026: sign or document an equivalent approach.

Draft guidance and reporting template on serious AI incidents

26 September 2025 · European Commission (AI Office)templatedraftArt 73Art 3(49)incidentsprovider duties

Draft guidance and reporting template published 26 September 2025 with consultation to 7 November 2025, delivered under Article 73(7), which required guidance by 2 August 2025. It clarifies the definition of a serious incident, gives examples and explains the interplay with other reporting regimes, aligned with the OECD AI Incidents Monitor. Article 73 itself obliges providers of high-risk systems to report within 15 days of awareness, 10 days for a death and 2 days for a widespread infringement, after which the market surveillance authority acts within 7 days. The final guidance is not yet published; build incident triage on the draft and the article text.

EU icons for labelling AI-generated content

10 August 2026 · European Commission (AI Office)templatevoluntaryArt 50(4)transparencydeployer duties

A free set of visual markers, last updated 10 August 2026, in four colour variants and three types: a basic icon, 'Fully AI-Generated' and 'Partially AI-Modified'. Deployers may use them to satisfy the Article 50(4) labelling duty for deepfakes and AI-generated text on matters of public interest, and they form an integral part of Section 2 of the transparency Code of Practice, whose signatories must follow the placement specifications. Use of the icons is optional and confers no automatic compliance, but the labelling requirement itself is not optional. No attribution to the Commission is needed.

Explanatory notice and template for the public summary of training content of GPAI models

24 July 2025 · European Commission (AI Office)templateArt 53(1)(d)gpaitransparencydata

Mandatory template published 24 July 2025 in all 24 official languages for the public summary that Article 53(1)(d) requires from every GPAI provider, including open-source providers, from 2 August 2025. It sets a common minimal baseline: a general overview of the model and data modalities, a list of data sources by category, and data processing aspects such as lawful access and opt-out respect. For web-scraped data providers must name the largest domains, the top 10 percent by volume, reduced to 5 percent or 1,000 domains for SMEs. Providers of models already on the market have until 2 August 2027.

General-Purpose AI Code of Practice and list of signatories

10 July 2025 · European Commission (AI Office), drafted by independent expertscode of practicevoluntaryArt 53Art 55Art 56gpaiprovider duties

Voluntary code published 10 July 2025 with three chapters: Transparency provides a Model Documentation Form for the Article 53 documentation duties, Copyright gives practical measures for the copyright policy required by Article 53(1)(c), and Safety and Security sets state-of-the-art practices for systemic-risk models under Article 55. The first two chapters apply to all GPAI providers, the third only to systemic-risk providers, and the Commission and the AI Board confirmed it as an adequate voluntary tool. The page lists 21 signatories, with one provider signing only the Safety and Security chapter, and signature is by form to the AI Office. Non-signatories must show compliance by other means.

Governance, enforcement and policy10 documents

AI Pact: collaborative network and voluntary pledges

25 September 2024 · European Commission (AI Office)policyvoluntaryArt 4Art 62Art 95literacygovernanceother

Voluntary Commission initiative with two pillars. Pillar I is an open network with webinars and exchange of practice; Pillar II, launched 25 September 2024, collects pledges in which providers and deployers commit to three core actions: adopting an AI governance strategy, mapping likely high-risk systems and promoting AI literacy among staff. Over half of pledgers add commitments on human oversight, risk mitigation and transparency of generated content, and the page lists more than 500 pledging organisations from large groups to SMEs. It creates no legal obligations and no presumption of conformity; use it for early engagement with the AI Office and for the living repository of practices.

Apply AI Strategy and AI in Science Strategy

8 October 2025 · European CommissionpolicyArt 57Art 62sandboxesgovernanceother

Two non-binding strategies adopted 8 October 2025. Apply AI accelerates adoption in key industries and the public sector, shortens time-to-market by linking infrastructure, data and testing facilities, launches a Frontier AI initiative, an Apply AI Alliance, an AI Observatory and the AI Act Service Desk. AI in Science creates RAISE, a virtual European institute pooling AI resources, backed by EUR 600 million from Horizon Europe for compute access and a plan to double annual Horizon Europe AI investment above EUR 3 billion. Relevant to practitioners mainly for the implementation support ecosystem: the Service Desk, Experience Centres for AI and sandbox access.

Appointment of the Scientific Panel of independent experts and the Advisory Forum

1 June 2026 · European Commission (AI Office)policyArt 67Art 68Art 90governancegpai

On 1 June 2026 the Commission announced the members of the two advisory bodies foreseen in Articles 67 and 68. The Scientific Panel has 60 independent experts serving two-year renewable terms, with at most three nationals per country, advising the AI Office on GPAI classification, systemic risks, evaluation methodologies and cross-border market surveillance, and able to issue qualified alerts under Article 90. The Advisory Forum brings academia, civil society and industry including SMEs, with the Fundamental Rights Agency, ENISA and the standardisation bodies as permanent members, also for two years. Neither body issues binding acts, but panel alerts can trigger AI Office action against a model.

Commission Opinion and AI Board adequacy assessment of the transparency Code of Practice

9 July 2026 · European Commission and European Artificial Intelligence BoardpolicyArt 50Art 56transparencygovernance

The Commission Opinion of 8 July 2026 and the AI Board adequacy assessment of 9 July 2026 find that the Code of Practice adequately covers Articles 50(2), (4) and (5) and facilitates their implementation. Adherence does not constitute conclusive evidence of compliance, but signatories gain a recognised route that market surveillance authorities across the Union will take into account regardless of where the operator is established. Participation stays voluntary and the AI Office will facilitate updates at least every two years. Keep this opinion with your Article 50 compliance file as the basis for relying on the code.

Commission proposal COM(2025) 836 for a Digital Omnibus on AI

19 November 2025 · European CommissionpolicyhistoricalArt 4Art 6Art 49Art 113governancehigh risk classification

The Commission's original proposal of 19 November 2025 (CELEX 52025PC0836), superseded by Regulation (EU) 2026/1744. It proposed linking high-risk application to the availability of standards with delays of up to 16 months for Annex III and 12 months for Annex I, a six-month transition for generative AI detectability, removal of registration for exempted systems, removal of the prescribed post-market monitoring plan, extension of SME relief to small mid-caps benefiting an estimated 8,250 additional companies, and an EU-level sandbox. Compare it with the enacted text to see where the co-legislators tightened the outcome.

Council press release: Council and Parliament agree to simplify and streamline AI rules

7 May 2026 · Council of the European UnionpolicyhistoricalArt 5Art 57Art 111Art 113governancehigh risk classification

Records the provisional trilogue agreement of 7 May 2026 on the Digital Omnibus on AI and is useful only as legislative history. It fixed the application dates of 2 December 2027 for stand-alone high-risk systems and 2 August 2028 for product-embedded systems, the sandbox deadline of 2 August 2027, a 2 December 2026 date for generative-content transparency solutions, the new ban on AI-generated non-consensual intimate content and child sexual abuse material, the extension of SME relief to small mid-caps, and the reinstatement of registration for exempted Annex III systems. Cite it for the negotiating record, not for the law.

Council press release: Council gives final green light to simplified AI rules

29 June 2026 · Council of the European UnionpolicyhistoricalArt 5Art 57Art 113governancehigh risk classification

Confirms the Council's final adoption of the Omnibus on 29 June 2026 as part of the Omnibus VII package, with entry into force on the third day after Official Journal publication. It restates the 2 December 2027 and 2 August 2028 high-risk dates, the December 2026 start of the sexual deepfake and CSAM prohibitions, the 2 December 2026 transparency transition (grace period reduced from six to three months in the final text), the 2 August 2027 sandbox deadline, the machinery exemption from direct application and the mechanism for resolving overlaps with medical device, toy, lift and watercraft legislation. Legislative history only.

European AI Office and Commission Decision C(2024) 390 establishing it

24 January 2024 · European CommissionpolicyArt 64Art 74-75Art 88-94governancegpaienforcement

The AI Office was created within DG CNECT by Commission Decision of 24 January 2024 and now employs more than 125 staff across six units, from Regulation and Compliance to AI Safety and AI in Health and Life Science, plus a Lead Scientific Adviser and an International Affairs Adviser. It supervises GPAI models under Articles 88 to 94, drafts codes of practice, guidelines and implementing and delegated acts, and since the Omnibus of 27 July 2026 holds exclusive competence over AI systems built on GPAI models and AI in very large online platforms. It is the counterpart for any GPAI provider and for complaints in its remit.

European Artificial Intelligence Board

10 September 2024 · European Commission (AI Office secretariat) and Member StatespolicyArt 65Art 66Art 4(3)governance

The Board established by Articles 65 and 66 met first on 10 September 2024 and has held nine documented meetings to September 2026. It comprises one representative per Member State, with the EDPS and EEA-EFTA states as observers, chaired by a Member State and supported by the AI Office. It advises on guidelines and draft delegated and implementing acts, has adopted adequacy assessments of both codes of practice, runs subgroups on standards, policy topics and the interplay with the medical device regulations, and must adopt AI literacy recommendations under the amended Article 4(3). Its opinions are non-binding but shape how national authorities apply the Act.

The enforcement framework of the AI Act

31 July 2026 · European Commission (AI Office)policyArt 70Art 74-75Art 85-88Art 99-101enforcementpenaltiesgovernance

Explains how enforcement is shared from 2 August 2026 between the AI Office, the EDPS for Union institutions and national market surveillance authorities. The AI Office supervises GPAI models and, after the Omnibus, systems built on them and AI in very large online platforms, using information requests, model evaluations, interviews and inspections. Penalty ceilings are EUR 35 million or 7 percent of worldwide turnover for prohibited practices, EUR 15 million or 3 percent for GPAI and other operator breaches, and EUR 7.5 million or 1 percent for misleading information. The deepfake and CSAM bans apply from 2 December 2026.

Standards2 documents

AI Act standardisation: standardisation request C(2023)3215 as amended by C(2025)3871

22 May 2023 · European CommissionstandardsArt 40Art 41Art 8-15Art 17standardsconformity

Commission Implementing Decision C(2023)3215 of 22 May 2023 asked CEN and CENELEC for harmonised standards in ten areas: risk management, governance and quality of datasets, record keeping, transparency, human oversight, accuracy, robustness, cybersecurity, quality management and conformity assessment. Decision C(2025)3871 amended it after the original 30 April 2025 delivery date passed. Standards remain voluntary but, once cited in the Official Journal under Article 40, give a presumption of conformity with Chapter III Section 2, with Article 41 common specifications as the fallback. The first deliverable, prEN 18286 on quality management systems, entered public enquiry on 30 October 2025, so track OJ citations before relying on any standard.

CEN-CENELEC JTC 21 news: EN 18286 and the AI Act standards programme

9 July 2026 · CEN-CENELEC JTC 21standardsdraftArt 17Art 40Art 9-15standardsconformity

The joint technical committee's news feed is the primary status source for the harmonised standards. Milestones: technical report CEN/CLC/TR 18115:2024 on data governance and quality published 6 November 2024; a technical report on conformity assessment published 18 December 2024; prEN 18286 'Quality management system for EU AI Act regulatory purposes' reached enquiry on 10 November 2025; further drafts opened for public consultation on 9 April 2026 and 8 May 2026; and on 9 July 2026 JTC 21 announced EN 18286 for publication in July 2026. A published EN gives no presumption of conformity until cited in the Official Journal, so monitor both.

EDPB and EDPS9 documents

EDPB Guidelines 02/2026 on anonymisation

8 July 2026 · European Data Protection Boardedpb edpsconsultationArt 10Art 59Art 2(7)data

Adopted 8 July 2026 alongside the web-scraping guidelines, with consultation until 30 October 2026. They set a three-criterion test for anonymous data: no singling out of a record, no linkage and no inference, assessed either contextually against the capabilities of the actual recipient or under a simplified approach that disregards those differences. For AI Act work they determine whether training, validation and testing datasets under Article 10 and data used in sandboxes under Article 59 still contain personal data, and they operationalise the anonymity threshold that Opinion 28/2024 applied to models. Treat anonymisation claims in supplier documentation against this test.

EDPB Guidelines 03/2026 on web scraping for the development of generative AI models

8 July 2026 · European Data Protection Boardedpb edpsconsultationArt 53(1)(c)Art 10Art 2(7)datagpai

Adopted at the 8 July 2026 plenary for public consultation until 30 October 2026. The guidelines confirm that the GDPR applies to collection, storage, organisation and retrieval of scraped personal data, require purpose limitation, transparency, minimisation and accuracy with timestamping and validation, clarify legitimate interest as the basis for training, and require both an Article 6 basis and an Article 9 exception for special-category data, citing GC and Others (C-136/17) for incidental collection with safeguards. They complement the copyright policy and training-content summary duties in Article 53. Providers scraping for training should align data governance with them now, before the final version.

EDPB Opinion 28/2024 on certain data protection aspects related to the processing of personal data in the context of AI models

18 December 2024 · European Data Protection Boardedpb edpsArt 10Art 53Art 2(7)datagpai

Article 64(2) GDPR opinion adopted 18 December 2024 at the request of the Irish supervisory authority. It holds that an AI model trained on personal data is anonymous only where identification of individuals or extraction of their data through queries is very unlikely, assessed case by case; sets a three-step test for legitimate interest in training and deployment, with conversational agents and cybersecurity as acceptable purposes when strictly necessary and balanced; and warns that models built on unlawfully processed data may face deployment restrictions unless properly anonymised. It does not implement the AI Act but governs the data side that Article 2(7) leaves to the GDPR.

EDPB Report of the work undertaken by the ChatGPT Taskforce

23 May 2024 · European Data Protection Boardedpb edpsArt 53Art 2(7)datagpai

Report adopted 23 May 2024 by the taskforce created in April 2023 to coordinate national investigations into ChatGPT. It sets out preliminary common positions on lawfulness of web scraping and training, the role of legitimate interest with balancing safeguards, fairness, transparency towards data subjects whose data were scraped, accuracy of outputs and the handling of access, rectification and erasure requests, and notes the shift to one-stop-shop supervision after the provider's Irish establishment in February 2024. Not binding, but it is the origin of the positions later formalised in Opinion 28/2024 and the 2026 web-scraping guidelines.

EDPB Statement 3/2024 on data protection authorities' role in the Artificial Intelligence Act framework

16 July 2024 · European Data Protection Boardedpb edpsArt 70Art 74(8)Art 77governanceenforcementnot fetched

Statement adopted 16 July 2024, before the Act entered into force, addressed to Member States designing their supervision. The EDPB recommends that data protection authorities be designated as market surveillance authorities for high-risk AI systems in the Annex III areas likely to affect fundamental rights, as Article 74(8) already requires for law enforcement, migration, border control and justice, that they serve as single points of contact, and that clear procedures be set for cooperation between DPAs, other market surveillance authorities and the AI Office. It is non-binding; several Member States followed it in part, so check the national designation.

EDPB Support Pool of Experts report: AI Privacy Risks and Mitigations in Large Language Models

10 April 2025 · European Data Protection Board (Support Pool of Experts), author Isabel Barberaedpb edpsreferenceArt 9Art 10Art 26Art 53datagpaideployer duties

A 99-page expert report published April 2025 that the EDPB states is not a formal Board position. It maps privacy risks across the eight lifecycle phases of ISO/IEC 22989 and 5338, three service models (LLM as a service, off-the-shelf, self-developed) and six data-flow stages, sets a three-stage risk methodology of identification, estimation and control, and catalogues over 70 technical and organisational mitigations split by provider and deployer role, with three worked use cases. It maps to GDPR Articles 25, 32 and 35 and to the AI Act's provider and deployer roles. Use it as a practical companion to Article 9 risk management and DPIAs for LLM deployments.

EDPB-EDPS Joint Opinion 1/2026 on the proposal for a Digital Omnibus on AI

20 January 2026 · European Data Protection Board and European Data Protection Supervisoredpb edpsArt 4aArt 10(5)Art 74Art 49datagovernancenot fetched

Joint opinion on COM(2025) 836 adopted in January 2026. The Board and Supervisor accepted the objective of simplification but asked that any processing of special categories of personal data for bias detection remain bound by strict necessity, pseudonymisation, access controls and deletion, that the exception not extend beyond high-risk systems without justification, that data protection authorities keep their supervisory role for AI affecting fundamental rights and be consulted where the AI Office takes over GPAI-based systems, and that registration of exempted Annex III systems be kept. The final Article 4a reflects the strict-necessity and safeguard conditions. Non-binding, but it signals how DPAs will read Article 4a.

EDPB-EDPS Joint Opinion 5/2021 on the proposal for an Artificial Intelligence Act

18 June 2021 · European Data Protection Board and European Data Protection Supervisoredpb edpshistoricalArt 5Art 70Art 2(7)prohibitionsgovernance

Joint opinion of 18 June 2021 on the Commission's April 2021 proposal, now legislative history. The two bodies called for a general ban on any use of AI for automated recognition of human features in publicly accessible spaces, a ban on social scoring, a ban on inferring emotions except for narrow cases and a ban on biometric categorisation by protected characteristics, and asked that data protection authorities be the national supervisory authorities and the EDPS the authority for Union institutions. The enacted Article 5 adopted narrower prohibitions. Read it to understand why DPAs still press for a fundamental-rights reading of the Act.

EDPS orientations on generative AI for EU institutions, bodies, offices and agencies

3 June 2024 · European Data Protection Supervisoredpb edpsArt 2(7)Art 26Art 4datadeployer dutiesgpainot fetched

First orientations published 3 June 2024 and revised in an expanded second version in October 2025, addressed to the Union institutions the EDPS supervises under Regulation (EU) 2018/1725 and under the AI Act as their market surveillance authority. Structured as practical questions: when generative AI processes personal data, the role of the data protection officer, when a DPIA is needed, lawful basis, minimisation, accuracy, transparency, automated decisions, fair processing, individual rights and security. Non-binding for private operators, but they show the supervisory expectations a deployer of a general-purpose AI system should meet and mirror the deployer duties in Article 26.

National implementation6 documents

France: DGCCRF as coordinating authority and single point of contact under a pending legislative proposal

17 June 2026 · Government of Francenational lawdraftArt 70Art 77governanceenforcement

France has published a legislative proposal, not yet adopted as of June 2026, for a decentralised model in which the Directorate-General for Competition, Consumer Affairs and Fraud Control (DGCCRF) coordinates market surveillance and serves as single point of contact, with existing sectoral regulators given a broadened scope as market surveillance and notifying authorities; the Commission's list marks DGCCRF as pending final adoption. Three fundamental rights authorities are designated, and the CNIL continues to publish AI Act and GDPR guidance for developers. Operators in France should track the bill for the penalty regime and the final split of competences between DGCCRF, CNIL and sector regulators.

Germany: KI-Marktueberwachungs- und Innovationsunterstuetzungsgesetz (KI-MIG) and Bundesnetzagentur designation

29 July 2026 · Bundesnetzagentur (Germany)national lawArt 70Art 57Art 99governanceenforcementsandboxes

Germany's implementing act, approved by the Federal Cabinet as a draft on 10 February 2026 and in force 29 July 2026, makes the Bundesnetzagentur the market surveillance authority, single point of contact, complaints body, operator of a regulatory sandbox for SMEs and start-ups and national AI service desk. It supervises AI in radio equipment, worker management, critical infrastructure and education, transparency obligations and prohibited practices, while the financial sector stays with BaFin, media with the state media authorities, and harmonised product sectors keep their existing supervisors. Germany lists 20 fundamental rights authorities. Operators in Germany now have a competent authority to notify and to report incidents to.

Ireland: S.I. No. 366 of 2025 and the designated competent authorities

17 June 2026 · Government of Irelandnational lawArt 70Art 28Art 77governanceenforcement

Ireland implemented a decentralised model through Statutory Instrument No. 366 of 2025, designating 15 sectoral market surveillance authorities with the Minister for Enterprise, Tourism and Employment as single point of contact and four notifying authorities: that Minister, the Minister for Transport, the Health Products Regulatory Authority and the Commission for Communications Regulation. Nine fundamental rights authorities are listed, a National AI Office was planned as the central coordinating authority by 2 August 2026, and the Commission's list of 7 September 2026 now names the AI Office of Ireland. Operators established in Ireland, including many GPAI providers, should map each of their systems to the relevant sectoral regulator.

Italy: Law No. 132/2025 on artificial intelligence

10 October 2025 · Italian Parliamentnational lawArt 70Art 57Art 99governanceenforcement

Italy was the first Member State to pass a comprehensive implementing law: Law No. 132/2025, 'Disposizioni e deleghe al Governo in materia di intelligenza artificiale', in force 10 October 2025. It designates the National Cybersecurity Agency (ACN) as market surveillance authority and single point of contact and the Agency for Digital Italy (AgID) as notifying authority, lists 5 fundamental rights authorities, and adds national sector rules on health, work, professions, justice and minors together with delegations to the Government for further decrees and new criminal provisions on unlawful dissemination of AI-generated content. Operators in Italy must read the national layer alongside the Act, especially in employment and healthcare.

Netherlands: decentralised supervision with RDI as single point of contact and draft implementing law

17 June 2026 · Government of the Netherlandsnational lawdraftArt 70Art 74(8)Art 77governanceenforcement

The Netherlands published draft implementing legislation in April 2026 confirming a decentralised model of ten sectoral market surveillance authorities, among them the Data Protection Authority, the State Inspectorate for Digital Infrastructure (RDI), the Financial Markets Authority and the central bank, with the same ten acting as notifying authorities and RDI as single point of contact; six fundamental rights authorities are listed. The Commission's list marks RDI as pending final adoption. The Dutch DPA has an early-warning role on algorithms and publishes AI Act guidance of its own. Operators in the Netherlands should expect the DPA to supervise fundamental-rights-sensitive high-risk uses in line with Article 74(8).

Spain: Spanish Artificial Intelligence Supervisory Agency (AESIA) and the draft AI governance law

17 June 2026 · Government of Spainnational lawdraftArt 70Art 57Art 99governanceenforcementsandboxes

Spain established AESIA in 2023 as the first dedicated national AI supervisory agency and designates it as market surveillance authority and single point of contact, with sectoral authorities participating and 20 fundamental rights authorities listed; the Commission's list still marks the designation as pending final adoption. The draft 'Ley para el buen uso y la gobernanza de la Inteligencia Artificial' would confirm this model, name the Directorate-General for Artificial Intelligence as notifying authority and set the national penalty regime, but was still pending in June 2026. Spain also ran the first national sandbox pilot. Until the law passes, rely on AESIA guidance and the Act directly.

Reference tools12 documents

AI Act Service Desk and Single Information Platform

8 October 2025 · European Commission (AI Office)reference toolreferenceArt 62(3)othergovernance

Launched 8 October 2025 with the Apply AI Strategy as the central hub the Act foresees in Article 62(3). It offers a Compliance Checker to determine obligations, an AI Act Explorer through 13 chapters, 180 recitals and the annexes, FAQs built from AI Pact webinars and stakeholder submissions, a high-risk guideline explorer, a national resources section and a submission form for individual questions answered by experts coordinating with the AI Office. Initially in English, French and German with all 24 languages planned for early 2026. Answers are informational and non-binding; note that some explorer pages still show pre-Omnibus text.

AI Act Service Desk explorer and compliance checker (Article 99 page with Omnibus notice)

8 October 2025 · European Commission (AI Office)reference toolreferenceArt 99Art 101penaltiesother

The Commission's own article-by-article explorer across 13 chapters, 180 recitals and the annexes in six interface languages, paired with the official compliance checker for AI systems and GPAI models. The Article 99 page shows penalty ceilings of EUR 35 million or 7 percent of worldwide turnover for Article 5 breaches, EUR 15 million or 3 percent for other operator and notified body breaches and EUR 7.5 million or 1 percent for misleading information, the lower figure applying to SMEs. It carries the notice that the provision was amended by the Digital Omnibus and the displayed text is not yet updated, so treat it as pre-Omnibus until that notice goes.

AI Act Service Desk: timeline for the implementation of the EU AI Act

27 July 2026 · European Commission (AI Office)reference toolreferenceArt 113Art 111Art 57governancehigh risk classification

The Commission's official post-Omnibus timeline. Entry into force 1 August 2024; definitions, literacy and prohibitions 2 February 2025; GPAI obligations and governance 2 August 2025; transparency rules and enforcement of prohibitions, GPAI, transparency and literacy 2 August 2026; the sexual deepfake and CSAM prohibitions and the marking deadline for pre-existing generative systems 2 December 2026; at least one national sandbox per Member State 2 August 2027; Annex III high-risk rules 2 December 2027; Annex I product-embedded high-risk rules 2 August 2028. Use it as the authoritative date list when the explorer text lags behind the amendments.

AI Act complaints tool, whistleblower tool and downstream provider channel

31 July 2026 · European Commission (AI Office)reference toolreferenceArt 85Art 87Art 89(2)enforcementgovernance

Three channels opened for the start of enforcement on 2 August 2026. The complaints tool lets any natural or legal person report alleged infringements by providers or deployers within the AI Office's exclusive competence under Article 85; complainants receive a reference number, submissions are confidential, and with consent the AI Office forwards matters to national market surveillance or fundamental rights authorities. The whistleblower tool, live since 25 November 2025, gives anonymous reporting to persons professionally connected to an operator under Article 87, and a separate channel lets downstream providers raise Article 53 to 55 concerns about integrated GPAI models under Article 89(2). Reflect these in internal speak-up procedures.

AI Act implementation timeline (artificialintelligenceact.eu)

27 July 2026 · Future of Life Institutereference toolreferenceArt 113Art 111Art 112Art 97governanceother

Independent timeline that lists every Commission and Member State deadline with its article, beyond the core application dates. It records guidance on Articles 8(2), 9(10) and 17(3) due 1 August 2027, post-market monitoring guidance and template due 2 September 2027, notified body applications under Article 43(3) by 28 January 2028, the Article 112 evaluation reports of 2 August 2028 and 2 August 2029, public-authority legacy systems by 2 August 2030, Annex X systems by 31 December 2030 and expiry of delegated powers on 1 August 2029 and 27 July 2031. Use it to plan supplier and audit cycles.

EU AI Act Compliance Checker (artificialintelligenceact.eu)

3 July 2025 · Future of Life Institutereference toolreferenceArt 2Art 5Art 6Art 51scopehigh risk classification

Interactive questionnaire that walks through operator role (provider, deployer, distributor, importer, authorised representative, product manufacturer), prohibited practices, high-risk classification and GPAI status and returns a tailored obligation summary as a PDF flowchart or by email. It was last substantially updated 3 July 2025, before the Digital Omnibus, so its high-risk dates and registration answers need checking against Regulation (EU) 2026/1744. The site reports over 150,000 monthly visitors and more than 40,000 newsletter subscribers, is not affiliated with the Union and recommends professional legal advice. Suitable as a first triage, not as a record of a classification decision.

EU AI Act Explorer (artificialintelligenceact.eu)

27 July 2026 · Future of Life Institutereference toolreferenceArt 1-113Annex I-XIVotherscope

Independent, free explorer maintained by the Future of Life Institute, explicitly not associated with the Union. It presents all 113 articles across 13 chapters, 14 annexes and 180 recitals in 24 languages with keyword search, hyperlinked cross-references with peek view, paragraph-level permalinks and a chatbot that answers from the text with citations. Unlike the Commission's own explorer it already shows the law as amended by the Digital Omnibus, which it records as amending 42 articles and 3 annexes and applying since 27 July 2026. Use it for the consolidated text and cite the Official Journal for anything formal.

European Parliament legislative train: Digital Omnibus on AI

20 June 2026 · European Parliamentreference toolreferenceArt 113governanceother

Procedure file 2025/0359(COD) tracking COM(2025) 836 from the proposal of 19 November 2025 through the Council general approach of 13 March 2026, the trilogue agreement of 7 May 2026, Coreper endorsement of 13 May 2026, the IMCO-LIBE committee vote of 2 June 2026 and the plenary adoption of 16 June 2026 by 423 votes to 57 with 174 abstentions. Rapporteurs were Arba Kokalari (EPP) and Michael McNamara (Renew). Use it to locate the committee reports and amendments when the final text needs interpretation against negotiating intent.

Market surveillance authorities and single points of contact under the AI Act

7 September 2026 · European Commission (AI Office)reference toolreferenceArt 70Art 74Art 77enforcementgovernance

The Commission's consolidated list of the national market surveillance authorities and single points of contact that Member States had to designate by 2 August 2025 under Article 70, updated 7 September 2026, with a companion page listing fundamental rights authorities under Article 77. It names, among others, Bundesnetzagentur for Germany, the National Cybersecurity Agency for Italy, AESIA for Spain, the AI Office of Ireland, the Rijksinspectie Digitale Infrastructuur for the Netherlands, DGCCRF for France, the Agency for Digital Government for Denmark, Traficom for Finland and KRiBSI for Poland; asterisks mark designations awaiting final national adoption. Check it to identify your supervisor and the recipient of Article 73 incident reports.

National implementation plans and authorities overview (all Member States)

17 June 2026 · Future of Life Institute (artificialintelligenceact.eu)reference toolreferenceArt 70Art 77Art 99governanceenforcement

Independent tracker updated 17 June 2026 rating each Member State as clear, partially clear or unclear on designation of market surveillance and notifying authorities, national implementing law and sandboxes. As of that date 9 Member States had clearly designated both authorities, 12 had proposals and 6 had none, against the 2 August 2025 deadline in Article 70, while all 27 had designated fundamental rights authorities by 2 November 2024 under Article 77. It records adopted laws in Italy, Denmark (Law 467/2025, in force 2 August 2025), Finland (Law 1377/2025, in force 1 January 2026), Hungary and Slovenia. Not official; verify against the Commission's list.

Repository of AI literacy practices (living repository)

27 July 2026 · European Commission (AI Office)reference toolreferenceArt 4literacy

Searchable collection of AI literacy practices submitted by providers and deployers, filterable by organisation size, sector, country, practice type (training, awareness events, guidance materials, workshops, peer learning) and implementation status. The AI literacy Q&A records more than 40 initiatives gathered from AI Pact pledgers between December 2024 and February 2025 and from wider organisations between April and June 2025. It is a reference tool with no legal effect: replicating a listed practice gives no presumption of compliance with Article 4. Use it to benchmark the scope and format of your own programme.

Standard setting overview (artificialintelligenceact.eu)

21 July 2025 · Future of Life Institutereference toolreferenceArt 40Art 41Art 8-15standardsconformity

Independent explainer updated 21 July 2025 on how harmonised standards work under the Act. It documents the standardisation request C(2023)3215 of 22 May 2023 with its missed delivery date of 30 April 2025 and the amending decision C(2025)3871 of June 2025 setting 31 August 2025, links the live CEN-CENELEC work-programme dashboard, and explains the presumption of conformity under Article 40 against the Commission's Article 41 power to adopt common specifications, which the Commission had not signalled using. It notes that European standards leverage ISO/IEC work such as ISO/IEC 42001 and 23894. Written before the Omnibus, so its 2026 and 2027 dates are superseded.

Sources: every entry links to its primary page, the AI Act Explorer for the provisions and the issuing body for the documents. The printable digest in the site's outputs folder lists all 190 numbered sources. Snapshot 19 September 2026.