The EU AI Act, part by part
Which part applies to your AI system decides everything else. Start with the screening, or read the part you need.
- prohibited AI practices (Article 5): Some uses of AI are banned outright in the EU. If any of these describe your system, the use has to stop; it can't be fixed with documentation.
- high-risk AI systems (Annex III): Annex III lists areas where AI is high-risk, such as hiring, credit, education and access to essential services. High-risk systems need risk management, data governance, logging, human oversight and documentation.
- high-risk AI in regulated products (Annex I): AI that is a safety component of a product already covered by EU product-safety law (machinery, medical devices, toys and others) is high-risk under Annex I.
- transparency obligations (Article 50): Chatbots must tell people they're talking to AI, and AI-generated or manipulated content must be marked. These duties apply even when the system isn't high-risk.
- general-purpose AI (GPAI) models: If you provide a general-purpose AI model (one that can be used for many tasks and built into other systems), you have your own set of obligations: technical documentation, information for downstream providers, a copyright policy and a training-data summary.
- Timeline: when each obligation applies.