A practical overview of the EU AI Act, its risk-based structure, affected actors and phased application.
Start with the system
List where AI is developed, placed on the market, put into service or used. Document the intended purpose, users and context before making a risk assessment.
- Describe the system and intended purpose
- Identify who provides and who deploys it
- Check whether prohibited practices, high-risk rules or transparency duties may be relevant
A risk-based structure
The Act addresses prohibited practices, high-risk systems, certain transparency situations and general-purpose AI models. A minimal-risk application does not automatically face the same obligations as a high-risk system.
Compare risk categories ↗The rules apply in phases
AI literacy and initial prohibitions began applying in February 2025. General-purpose AI obligations followed in August 2025. Many other rules began in August 2026, with later dates for high-risk categories following the 2026 amendments.
See the verified timeline ↗Who can be affected?
The Act addresses different actors in the AI value chain, including providers, deployers, importers and distributors. Its territorial reach is not limited to organisations established in the EU: placing a system or model on the Union market, using a system in the Union, or producing output used in the Union can be relevant under Article 2. A team should establish the entity, activity and geography before assuming it falls outside the rules.
Map provider responsibilities ↗What does risk-based mean in practice?
The rules are not a single licence for all AI. Article 5 prohibits defined practices. Article 6 and the Annexes identify high-risk systems. Article 50 creates particular transparency duties. Chapter V concerns general-purpose AI model providers. These layers may overlap in one product, while many ordinary uses do not meet the high-risk definition. Classification begins with the intended purpose and actual operating context, followed by the precise provision.
Work through the risk categories ↗A simple example of the distinction
Consider a general-purpose model integrated into a recruitment screening tool. The model provider has a separate Chapter V question. The company offering the screening system must assess whether its intended employment use is listed in Annex III and what role it plays. The employer using the tool must consider deployer duties. Calling the entire chain “an AI tool” conceals the distinct questions and should not substitute for reviewing the precise design and use.
Compare provider and deployer roles ↗What should an organisation do first?
Create an inventory of systems and models, record intended uses, name the provider and deployer, and flag uses needing specialist review. Keep an assessment record with the source provision, reasoning, reviewer and date. Then plan controls and application dates. This is an organising method, not proof of compliance; the right legal analysis depends on the facts of each deployment.
- Record the system and its intended purpose
- Separate system, model and actor roles
- Check the current consolidated legal text and applicable date
This guide is an orientation, not a legal determination. Check the current legal text and official implementation guidance for your system.
Read the AI Act ↗European Commission overview ↗