Skip to content

Running commentary · living document · revised 9 July 2026

AI Act

Regulation (EU) 2024/1689 on artificial intelligence. What it does, when which obligations start, and a commentary on each of the 113 articles, with the full text. I hold the citations against the official English text, not against second-hand summaries.

TL;DR

The AI Act is the world’s first comprehensive horizontal legal framework for artificial intelligence. It governs AI not by what it is but by where and for what it is used: it bans eight practices outright, lets listed high-risk uses onto the market only with technical requirements and conformity assessment on the model of CE marking, disposes of chatbots and synthetic content with a duty to inform, and leaves the rest alone. Foundation models of the GPT type have a special regime. The obligations phase in from February 2025 to 2028, and the fines climb to EUR 35 million or 7% of worldwide turnover.

What the regulation is about

The regulatory technique is product-based. The AI Act knows no licensed profession of “AI provider”; it knows a product, its intended purpose and its risk class. In this it resembles the regime for machinery or medical devices and differs from the professional-body regulation of the sort that governs the legal profession. Obligations hang on roles in the chain. The provider (who develops the system and places it on the market) carries the most, the deployer (who uses it at work) less, the importer and distributor something. The roles are not static: anyone who re-labels a third party’s system or changes its purpose takes over the provider’s obligations.

The risk pyramid has four tiers. Prohibited practices (Article 5) may not enter the EU at all. High-risk systems (Article 6, Annexes I and III: biometrics, education, employment, credit, the justice system and others) get through only with risk management, quality data, documentation, logs, human oversight and conformity assessment. Systems that meet people (chatbots, content generators, deepfakes) have the information duties of Article 50. Everything else stays free, with voluntary codes.

Prohibited practices Article 5 · banned since 2 February 2025
High-risk systems Article 6 + Annexes I and III · from 2 December 2027 / 2 August 2028
Transparency obligations Article 50 · from 2 August 2026
Minimal risk no special obligations · voluntary codes (Article 95)
The higher up, the harsher the regime. The high-risk deadlines are those set by Regulation (EU) 2026/1744.

Running across all this is a separate track for general-purpose AI models (GPAI): documentation, a copyright policy and a summary of the training data for all of them, and a stricter regime of evaluations and incident reporting for models with systemic risk above the 10^25 FLOPS threshold. Enforcement against them is kept by the Commission through the AI Office; the rest is supervised by the national authorities; high-risk systems are registered in a public database; and the persons affected have the right to complain and to an explanation of a decision.

One thing the regulation deliberately does not do: it does not place private legal-advice systems among the high-risk ones (Annex III, point 8 is aimed at judicial authorities and comparable use in out-of-court dispute resolution). That does not put legal AI entirely outside high risk, though. It can become high-risk by another route, if it falls into employment, credit, migration, public benefits or law enforcement. What follows from that gap is tracked by hypothesis H3 on the research map and the Nippon v. OpenAI case.

Who you are in the chain

Obligations follow from the role, not from the size of the business. You can have several roles at once, and geography does not decide: the regulation reaches entities outside the EU too, where the output of their system is used in the Union.

Provider

Develops the system (or has it developed) and places it on the market or puts it into service under its own name or trademark, whether for payment or free of charge. Carries the largest bundle of obligations (Article 16).

Deployer

Uses an AI system in the course of a professional activity. The most common role for an ordinary business, with obligations in Article 26 and, for selected deployers, the FRIA under Article 27.

Importer

Places on the EU market a system bearing the name of an entity established outside the Union (Article 23).

Distributor

A further link in the chain that makes the system available on the EU market and is neither the provider nor the importer (Article 24).

Product manufacturer

Places on the market a product under Annex I with an embedded high-risk system under its own name, and then carries the provider’s obligations (Article 25(3)).

Authorised representative

An entity in the EU mandated in writing by a provider from a third country; holds the documentation and is the authorities’ point of contact (Article 22).

This is how the role most often switches. Anyone who re-labels a third party’s system with their own trademark, substantially modifies it, or changes its purpose to a high-risk one, becomes a provider with everything that entails (Article 25).

Is your system high-risk?

A preliminary classification under Article 6, step by step from the top down. Once you reach a result, the branch ends.

1 A safety component of a product under Annex I with third-party conformity assessment?
YES
High-risk Article 6(1)
NO
2 Does the use fall into one of the areas of Annex III?
NO
Not high-risk
YES
3 Does the system profile natural persons?
YES
Always high-risk Article 6(3)
NO
4 A significant risk to health, safety or fundamental rights?
YES
High-risk
NO
5 Does the system perform only a narrow task under Article 6(3)?
YES
Not high-risk document the exception and register, Article 6(4) and Article 49(2)
NO
High-risk system
A first sieve under Article 6; the full wording of the questions is in the steps below. Once a branch reaches a result, it ends.

Step 1

Is the system a safety component of a product under Annex I (or itself such a product) and subject to third-party conformity assessment?

YesHigh-risk system (Article 6(1)).

NoGo to step 2.

Step 2

Does the use of the system fall into one of the areas of Annex III?

YesGo to step 3.

NoNot a high-risk system.

Step 3

Does the system profile natural persons?

YesAlways a high-risk system (Article 6(3), last subparagraph).

NoGo to step 4.

Step 4

Does the system present a significant risk of harm to health, safety or fundamental rights, among other things by materially influencing the outcome of decision-making?

YesHigh-risk system.

NoGo to step 5.

Step 5

Does the system meet at least one of the conditions in Article 6(3)? A narrow procedural task, improving the result of a human activity already completed, detecting decision-making patterns or deviations from them without replacing an earlier human assessment absent human review, or merely a preparatory task to an assessment.

YesNot a high-risk system. Document the exception before placing on the market and register the system (Article 6(4) and Article 49(2)).

NoHigh-risk system.

The chart is an indicative first sieve; borderline cases call for an assessment against the specific purpose of the system and the Commission’s guidelines under Article 96.

Obligations and deadlines

1 August 2024

The regulation entered into force (on the twentieth day after publication in the Official Journal). No obligations yet.

2 February 2025

Chapters I and II. The Article 5 prohibitions (eight prohibited practices at the time) and the AI-literacy obligation in Article 4 apply. The first date that hit ordinary businesses.

2 August 2025

General-purpose AI models (Chapter V), governance (Chapter VII), notifying authorities (Chapter III, Section 4), penalties (Chapter XII except Article 101) and confidentiality (Article 78). By this date the States had designated their national authorities (Article 70).

2 August 2026

General applicability. Transparency under Article 50 (chatbots, synthetic content, deepfakes) and the rights in Articles 85 and 86. High-risk systems under Annex III were to phase in too, but Regulation (EU) 2026/1744 pushed them back (see below).

2 December 2027

As amended by Regulation (EU) 2026/1744: the obligations for stand-alone high-risk systems under Annex III (originally 2 August 2026).

2 August 2028

As amended by Regulation (EU) 2026/1744: the obligations for AI embedded in regulated products under Article 6(1) and Annex I (originally 2 August 2027). As of 2 August 2027 the obligation remains to bring general-purpose AI models placed on the market before 2 August 2025 into line (Article 111(3), untouched by the amendment) and to have a national regulatory sandbox up and running (Article 57).

2030

The run-off of old systems: high-risk systems used by public authorities to be brought into line by 2 August 2030, and large-scale EU information systems under Annex X placed before 2 August 2027 by 31 December 2030 (Article 111).

The omnibus package: published (as of 9 July 2026)

The wait is over. Regulation (EU) 2026/1744 was published in the Official Journal on 24 July 2026 and, under its own Article 4, entered into force on the third day after publication, that is on 27 July 2026. It amends the AI Act in 43 points.

The phase-in of the high-risk obligations has moved: Annex III to 2 December 2027, AI in products under Annex I to 2 August 2028. The prohibitions, AI literacy, transparency and the general-purpose-model regime are not deferred.

Article 5 gained two new prohibitions applicable from 2 December 2026: non-consensual intimate material depicting an identifiable person (point (ba)) and child sexual abuse material (point (bb)). By the same date, generative systems already on the market must add machine-readable marking of their outputs under Article 50. Article 4 on AI literacy was replaced in full and now reads as an obligation of effort, not of result. Article 4a (processing sensitive data to detect and correct bias), Article 60a (testing in real-world conditions for Annex I products) and Articles 75a to 75d (the AI Office\u2019s supervisory and enforcement powers) were inserted. Articles 102 to 110 apply from 27 July 2026.

The Czech implementation

The AI Act applies directly, but national law fills in supervision, the sandbox, conformity assessment and enforcement. The Czech AI adaptation act, from the Ministerstvo průmyslu a obchodu (the Ministry of Industry and Trade), has been through interdepartmental consultation, and its effective date depends on the further course of the legislative process (as of 9 July 2026).

Under the bill as tabled, the single point of contact and the centre of market surveillance is to be the Český telekomunikační úřad (the Czech Telecommunication Office), supplemented sectorally by, among others, the Česká národní banka (the Czech National Bank) for financial services and the Úřad pro ochranu osobních údajů (the Data Protection Authority) where personal data is involved. The Úřad pro technickou normalizaci, metrologii a státní zkušebnictví (the Office for Standards, Metrology and Testing) is to act as the notifying authority for conformity assessment bodies, and it is also envisaged in the role of the national regulatory sandbox.

A detail that matters in practice: the AI Act itself sets no fine for failing to carry out a fundamental-rights impact assessment (the FRIA, Article 27); the article is missing from the list of penalties in Article 99(4). The Czech bill as tabled fills that gap with its own offence carrying a fine of up to EUR 7.5 million or 1% of turnover. Anyone deferring the FRIA on the strength of the missing sanction should reckon with the possibility that, under the enacted text of the Czech act, it may be there.

Practical preparation

The road to compliance need not start with a big project. Six steps that make sense in this order and cover the nearest deadlines. For the rules-and-training step, the open AI-literacy course (in Czech) on this site is useful, free under the CC BY 4.0 licence.

01

Inventory. Map where AI is actually used across the organisation, including the tools teams acquired on their own outside the official route.

02

Risk classification. Sort each use into the tiers of the pyramid, from a prohibited practice to a system with no special obligations. The chart above helps.

03

Determining the role. For each system, know whether you are a provider, a deployer, an importer or a distributor, and watch for a role switch under Article 25.

04

Contracts with suppliers. Deal with documentation, data, security, audit rights, incident reporting and the allocation of liability.

05

Rules and training. Internal rules for the use of AI and training for people. This also meets the AI-literacy obligation in Article 4, which has been running since 2 February 2025.

06

Documentation and monitoring. Compliance does not end at deployment. Models, uses and deadlines change; documentation and review have to run continuously.

Commentary on the provisions

All 113 articles, chapter by chapter, each with a short commentary right there. Open a provision and you also get the full text inside. The commentary deepens over time.

Chapter I · Articles 1–4

General provisions

Defines what the regulation regulates, whom it reaches and what language it speaks. This is where it is decided whether you are in the AI Act regime at all.

Art. 1 Subject matter

A dual purpose: a functioning internal market and trustworthy AI that protects health, safety and fundamental rights. The interpretive anchor reached for when reading every other provision teleologically.

Art. 2 Scope

Extraterritorial reach. It catches providers placing a system on the market in the EU regardless of where they are established, and providers and deployers in third countries where the system’s output is used in the EU. Outside the regime sit national security and defence, scientific research and development, pre-market activity, purely personal non-professional use, and in part open-source models. Member States may keep stronger protection for employees.

Art. 3 Definitions

The 68 definitions the whole regulation stands on. An AI system is recognised by its inference of outputs from inputs, a varying degree of autonomy and possible adaptiveness, which decides whether a given piece of software is in the regime at all. The load-bearing pair of roles is the provider (develops it, or has it developed, and places it on the market) and the deployer (uses it in the course of a professional activity). Most obligations hang on the provider.

Art. 4 AI literacy

Providers and deployers alike ensure a sufficient level of AI literacy among the staff working with AI, having regard to the context and the persons affected. It has applied since 2 February 2025 and is the most far-reaching obligation in the regulation, reaching even those who merely use AI. In practice it is met through training, internal rules and documentation of both. The AI Act’s harmonised fining tiers do not list Article 4 (Article 4 is absent from the list in Article 99(4)), so no direct fine from those tiers threatens for breaching it. National enforcement and non-monetary measures may still be relevant. The open AI-literacy course (in Czech) on this site serves to meet the obligation.

Chapter II · Article 5

Prohibited AI practices

A single article, but with the harshest penalty (EUR 35 million or 7% of turnover). Eight practices that are not allowed at all.

Art. 5 Prohibited AI practices

Prohibitions (a) to (h). Subliminal and manipulative techniques that materially distort decision-making; exploitation of vulnerabilities (age, disability, a social or economic situation); social scoring with unjustified consequences outside the original context; predicting criminality purely from personality profiling; the untargeted scraping of facial images from the internet and CCTV footage; inferring emotions in the workplace and in education (outside medical and safety reasons); biometric categorisation revealing sensitive traits; and real-time remote biometric identification in publicly accessible spaces for law enforcement. For the last of these, paragraphs 2 to 7 allow exhaustive exceptions (victims, an imminent threat to life, offenders in listed crimes) with the prior authorisation of a court or an independent authority. The practical test before deploying anything with AI is to run through those eight points. Regulation (EU) 2026/1744 added two more, points (ba) and (bb), applicable from 2 December 2026: non-consensual intimate material depicting an identifiable person, and child sexual abuse material. New paragraphs 1a and 1b spell out what counts as placing on the market and what technical safeguards a provider is expected to have.

Chapter III · Articles 6–49

High-risk AI systems

The core of the regulation, product regulation on the model of CE marking. Classification, technical requirements, obligations along the chain, notified bodies and the route to market.

Section 1 · classification (Articles 6–7)

Art. 6 Classification rules for high-risk AI systems

Two routes into high risk. The system is a safety component of a regulated product under Annex I with third-party conformity assessment (paragraph 1), or it falls into the areas of Annex III (paragraph 2), namely biometrics, critical infrastructure, education, employment, essential services and credit, law enforcement, migration, the administration of justice. Paragraph 3 provides a filter for systems with only a preparatory or ancillary role without significant risk, but the exception has to be documented and the system registered. Profiling of natural persons is always high-risk. The step-by-step decision chart is on the AI Act card.

Art. 7 Amendments to Annex III

The Commission may by delegated acts both add to and narrow the list of high-risk uses according to criteria of the severity and probability of harm. This is the mechanism by which Annex III will keep changing; tracking it is a continuing compliance obligation in itself.

Section 2 · requirements for the system (Articles 8–15)

Art. 8 Compliance with the requirements

The system meets the requirements of the section having regard to its intended purpose and the generally acknowledged state of the art. For products under Annex I, compliance is integrated into the sectoral procedures so that nothing is assessed twice.

Art. 9 Risk management system

A continuous, iterative process across the whole life cycle. Identifying foreseeable risks including reasonably foreseeable misuse, design measures, testing against metrics, and particular regard for persons under 18 and otherwise vulnerable groups.

Art. 10 Data and data governance

Training, validation and testing sets must be relevant, sufficiently representative and, to the best extent possible, free of errors, with data-governance practices from collection through labelling to the detection and mitigation of bias. Processing special categories of personal data to detect bias is allowed only under strict cumulative conditions. In practice the most expensive article in the regulation.

Art. 11 Technical documentation

Kept up to date before the system is placed on the market and thereafter, with content per Annex IV. Small and medium-sized enterprises may use the Commission’s simplified form.

Art. 12 Record-keeping

The system automatically logs events across the whole life cycle so that a risky situation, a substantial modification and the basis for post-market monitoring can be traced back.

Art. 13 Transparency and provision of information to deployers

Instructions for use setting out the system’s capabilities and limits, performance metrics, known risks, and the requirements for human oversight and maintenance. Without this article the deployer could not carry its own obligations under Article 26.

Art. 14 Human oversight

Oversight must be effective: the overseeing person understands the capabilities and limits, can interpret the output correctly, resist automation bias, and intervene or stop the system. For remote biometric identification, no action may be taken on the basis of the output alone without verification by at least two competent natural persons.

Art. 15 Accuracy, robustness and cybersecurity

Declared levels of accuracy in the instructions, robustness against errors and against attempts at misuse (data poisoning, adversarial inputs), and the handling of feedback loops in systems that learn in operation.

Section 3 · obligations along the chain (Articles 16–27)

Art. 16 Obligations of providers of high-risk AI systems

A summary catalogue. Ensure compliance with Section 2, have a quality management system, keep documentation and logs, undergo conformity assessment, draw up the declaration, affix the CE marking, register, take corrective action, cooperate with the authorities, and meet accessibility requirements under Directives (EU) 2016/2102 and 2019/882.

Art. 17 Quality management system

A written quality management system covering the compliance strategy, design and development, testing, data governance, risk management, post-market monitoring, incident reporting and communication with the authorities. The counterpart of the QMS from the world of medical devices.

Art. 18 Documentation keeping

The technical documentation, the QMS documentation, the declaration of conformity and the certificates kept available to the authorities for ten years after the system is placed on the market.

Art. 19 Automatically generated logs

Logs under the provider’s control are kept for a period appropriate to the purpose, at least six months.

Art. 20 Corrective actions and duty of information

Bring a non-conforming system into compliance, withdraw it from the market, disable it or recall it, and inform distributors, deployers, the authorised representative and importers.

Art. 21 Cooperation with competent authorities

On a reasoned request, demonstrate compliance and make the documentation and logs available in a language the authority understands.

Art. 22 Authorised representatives of providers of high-risk AI systems

A provider from a third country must have a written-mandated representative established in the EU who holds the documentation and is the authorities’ point of contact. The same logic as Article 27 GDPR.

Art. 23 Obligations of importers

Before placing a system on the market, verify that conformity assessment has been carried out, that documentation exists, that the system bears the CE marking and that the provider has a representative. The importer puts its name on the packaging and must not place a system it knows to be non-conforming.

Art. 24 Obligations of distributors

Verification of markings and documents, storage and transport that do not jeopardise conformity, and a duty to withdraw or report a system presenting a risk.

Art. 25 Responsibilities along the AI value chain

The most underestimated article in the regulation. Anyone who puts their own name on a third party’s high-risk system, substantially modifies it, or turns a general-purpose system’s purpose into a high-risk one, becomes a provider with all the obligations. The original provider hands over the documentation, and component suppliers conclude written cooperation agreements. This is exactly the way integrators building on other people’s models slip into the regime.

Art. 26 Obligations of deployers of high-risk AI systems

Use it in accordance with the instructions, entrust oversight to competent persons, ensure relevant input data, monitor operation, report incidents, keep logs for at least six months, inform workers and their representatives before deployment in the workplace, and inform the persons about whom the system helps to decide.

Art. 27 Fundamental rights impact assessment for high-risk AI systems

Public-body deployers, private providers of public services, and deployers in credit scoring and life insurance describe, before first use, the processes, the groups affected, the risks of harm, human oversight and corrective measures, and notify this to the supervisory authority. It builds on the DPIA from the GDPR and, where one already exists, is added to it.

Section 4 · notifying authorities and notified bodies (Articles 28–39)

Art. 28 Notifying authorities

Each State designates an authority to assess, notify and monitor conformity assessment bodies, with a guarantee of impartiality towards them.

Art. 29 Application of a conformity assessment body for notification

A conformity assessment body demonstrates its competence by accreditation or, where appropriate, other documentation.

Art. 30 Notification procedure

Notification to the Commission and the States is done electronically, with windows for objections; only then may the body act as notified.

Art. 31 Requirements relating to notified bodies

Independence from providers and competitors, confidentiality, expert staff, liability insurance, and internal processes proportionate to the size of the client.

Art. 32 Presumption of conformity with requirements relating to notified bodies

Accreditation under harmonised standards raises a presumption that the requirements of Article 31 are met.

Art. 33 Subsidiaries of notified bodies and subcontracting

Subcontracting of assessment only with the client’s consent and with the notified body retaining full responsibility.

Art. 34 Operational obligations of notified bodies

Assess proportionately, do not burden small providers needlessly, and keep the documentation available to the notifying authority.

Art. 35 Identification numbers and lists of notified bodies

The Commission assigns numbers and maintains a public list of notified bodies.

Art. 36 Changes to notifications

The procedure on loss of competence, suspension or withdrawal, and the fate of certificates already issued, including the transfer of files to another body.

Art. 37 Challenge to the competence of notified bodies

The Commission may investigate competence and require the State to take remedial action, including withdrawing the notification.

Art. 38 Coordination of notified bodies

Sectoral groups for sharing practice, so that assessment does not diverge between States.

Art. 39 Conformity assessment bodies of third countries

On equivalent conditions and on the basis of agreements, bodies established outside the EU may also carry out the activity.

Section 5 · standards, conformity, certificates, registration (Articles 40–49)

Art. 40 Harmonised standards and standardisation deliverables

Conformity with a harmonised standard raises a presumption of conformity with the requirements the standard covers. The practical route to compliance; standards for the AI Act are being drawn up in CEN/CENELEC at the Commission’s request.

Art. 41 Common specifications

Where standards are missing or insufficient, the Commission may by implementing act issue its own specifications with the same presumption effect.

Art. 42 Presumption of conformity with certain requirements

Two special presumptions. Training on data reflecting the deployment setting, for representativeness, and cybersecurity certification, for Article 15.

Art. 43 Conformity assessment

For biometrics under Annex III, point 1, the provider chooses between internal control under Annex VI and assessment with a notified body under Annex VII only where it has used harmonised standards or common specifications. Where such standards do not exist or it did not apply them in full, it must go the Annex VII route with a notified body. For the other areas of Annex III, internal control under Annex VI is enough. Systems in products under Annex I run under the sectoral procedures. A substantial modification of the system means a new assessment.

Art. 44 Certificates

Issued by notified bodies for a limited period, with the possibility of extension, suspension and withdrawal, against which an appeal procedure exists.

Art. 45 Information obligations of notified bodies

Reporting of certificates issued, refused, suspended and withdrawn to the notifying authority and sharing with the other bodies.

Art. 46 Derogation from conformity assessment procedure

On exceptional grounds of public security, the protection of life and health, the environment or key assets, the supervisory authority may authorise placing on the market without a completed assessment, temporarily and under control.

Art. 47 EU declaration of conformity

Through it the provider assumes responsibility for conformity for ten years, with content per Annex V.

Art. 48 CE marking

Visibly, legibly and indelibly, digitally for digital systems, with the number of the notified body where one was involved.

Art. 49 Registration

The provider registers in the EU database under Article 71 before placing the system on the market; systems exempted by the Article 6(3) filter and public-body deployers register too. Sensitive areas (law enforcement, migration) go into the non-public part.

Chapter IV · Article 50

Transparency obligations for providers and deployers of certain AI systems

The layer for AI that is not high-risk but meets people. For private AI chatbots, legal ones included, it is so far the only layer of the regulation that reaches them directly.

Art. 50 Transparency obligations for providers and deployers of certain AI systems

The obligations split by role. The provider ensures that a person can tell they are dealing with AI (unless it is obvious from the context) and that synthetic audio, image, video and text carry a machine-readable marking. The deployer informs persons exposed to emotion recognition or biometric categorisation, discloses the artificial origin of a deepfake (for manifestly artistic and satirical works an unobtrusive acknowledgement is enough), and labels AI text published to inform the public on matters of public interest, unless the text has undergone human editorial review and someone bears editorial responsibility for it. All of it clearly and distinguishably, at the latest at the first interaction, not buried in the terms. It is a duty to inform, not a requirement on the quality of the output; why that is not enough for legal advice is discussed in hypothesis H3 on the research map.

Chapter V · Articles 51–56

General-purpose AI models

The regime for foundation models of the GPT or Claude type, graded by systemic risk.

Art. 51 Classification of general-purpose AI models as general-purpose AI models with systemic risk

A model has systemic risk when its high-impact capabilities match the training-compute threshold of more than 10^25 floating-point operations, or when the Commission designates it as such of its own motion under the criteria in Annex XIII.

Art. 52 Procedure

The provider notifies the Commission of meeting the threshold within two weeks and may argue that the model nonetheless does not present systemic risk. The Commission maintains and publishes a list of such models.

Art. 53 Obligations for providers of general-purpose AI models

Technical documentation per Annex XI, information for downstream providers per Annex XII, a policy to comply with Union copyright law including respect for text-and-data-mining reservations, and a public summary of the training content per the AI Office template (24 July 2025, also in Czech). Open-source models get relief from the documentation, not from copyright and the summary.

Art. 54 Authorised representatives of providers of general-purpose AI models

Providers of general-purpose models outside the Union appoint a representative in the EU, the counterpart of Article 22.

Art. 55 Obligations of providers of general-purpose AI models with systemic risk

In addition, model evaluation including adversarial testing, the assessment and mitigation of systemic risks at EU level, the reporting of serious incidents to the AI Office, and cyber protection of the model and its infrastructure.

Art. 56 Codes of practice

The AI Office facilitates codes that make meeting the requirements of Chapter V practical; they were due by 2 May 2025. Adhering to a code is a way to demonstrate compliance until harmonised standards exist. The GPAI Code of Practice of 10 July 2025 (chapters on transparency, copyright, and safety and security) was endorsed by the Commission and the AI Board as a suitable voluntary tool and was signed by, among others, the large model providers.

Chapter VI · Articles 57–63

Measures in support of innovation

A counterweight to the obligations: sandboxes, real-world testing and relief for smaller players.

Art. 57 AI regulatory sandboxes

Each State sets up at least one sandbox, after the amendment by Regulation (EU) 2026/1744 by 2 August 2027, whether alone or jointly with other States. A controlled environment for development and testing under the authorities’ guidance, with a written report and evidence as the output, which count towards conformity assessment. Participation does not remove liability, but acting in good faith under the guidance protects against fines.

Art. 58 Detailed arrangements for, and functioning of, AI regulatory sandboxes

Uniform criteria and procedures are laid down by Commission implementing acts; for small and medium-sized enterprises access is to be free of charge in principle.

Art. 59 Further processing of personal data for developing certain AI systems in the public interest in the AI regulatory sandbox

Lawfully obtained personal data may be further processed in the sandbox to develop systems in a substantial public interest (health, the environment, energy, transport, public administration), in a separated environment, with deletion once it ends.

Art. 60 Testing of high-risk AI systems in real world conditions outside AI regulatory sandboxes

High-risk systems from Annex III may be tested outside the sandbox before being placed on the market, with a testing plan, registration, the informed consent of the subjects, and a cap of six months extendable once by a further six.

Art. 61 Informed consent to participate in testing in real world conditions outside AI regulatory sandboxes

The free, specific and documented consent of testing participants, with the right to withdraw at any time.

Art. 62 Measures for providers and deployers, in particular SMEs, including start-ups

Priority free access to the sandboxes, training, communication channels, and conformity-assessment fees proportionate to size.

Art. 63 Derogations for specific operators

Micro-enterprises may meet selected elements of the quality management system in a simplified way.

Chapter VII · Articles 64–70

Governance

The institutional architecture at both Union and national level.

Art. 64 AI Office

The Commission concentrates expertise and enforcement through the AI Office, which is at the same time the direct supervisor of general-purpose models.

Art. 65 Establishment and structure of the European Artificial Intelligence Board

One representative from each State, a coordinating body between the Commission and the national authorities.

Art. 66 Tasks of the Board

Uniform application of the regulation, opinions, recommendations and support for aligned administrative practice, including the sandboxes.

Art. 67 Advisory forum

Industry, small and medium-sized enterprises, academia and civil society advise the Board and the Commission, in a balanced composition.

Art. 68 Scientific panel of independent experts

An expert backbone for the Office; among other things it may issue a qualified alert about the systemic risk of a general-purpose model.

Art. 69 Access to the pool of experts by the Member States

States may draw on the same pool of experts for support of their own supervision.

Art. 70 Designation of national competent authorities and single points of contact

Each State designated, by 2 August 2025, at least one notifying authority and one market surveillance authority and a single point of contact, with a guarantee of resources and competences.

Chapter VIII · Article 71

EU database for high-risk AI systems

A public register of high-risk systems.

Art. 71 EU database for high-risk AI systems listed in Annex III

The Commission operates a public, machine-readable database of registrations under Article 49 with content per Annex VIII. Law enforcement and migration have a non-public section accessible only to the authorities.

Chapter IX · Articles 72–94

Post-market monitoring, information sharing and market surveillance

Life after being placed on the market, from monitoring through supervision to enforcement against general-purpose models.

Monitoring and incidents (Articles 72–73)

Art. 72 Post-market monitoring by providers and post-market monitoring plan for high-risk AI systems

The provider actively collects and evaluates operating experience under a plan that is part of the technical documentation; the Commission issues the template.

Art. 73 Reporting of serious incidents

The provider reports a serious incident to the authority of the State where it occurred, at the latest within 15 days, within 10 days in the event of death, and within 2 days for a widespread infringement or a disruption of critical infrastructure. Investigation and a report on the remedy follow.

Market surveillance (Articles 74–84)

Art. 74 Market surveillance and control of AI systems in the Union market

The market surveillance regime of Regulation (EU) 2019/1020 applies. The authorities have access to documentation, data and (under conditions) source code; for financial institutions the sectoral authorities supervise, and for biometrics for law enforcement the data protection authorities do.

Art. 75 Mutual assistance, market surveillance and control of general-purpose AI systems

Where a system builds on a general-purpose model from the same provider, the AI Office cooperates with the national supervisor so that competences do not overlap.

Art. 76 Supervision of testing in real world conditions by market surveillance authorities

The authorities oversee testing under Article 60 and may suspend or end it.

Art. 77 Powers of authorities protecting fundamental rights

Listed national fundamental-rights authorities receive access to documentation where they need it for their remit.

Art. 78 Confidentiality

Protection of intellectual property, trade secrets and source code in the exercise of supervision; the exchange of information between authorities only to the extent necessary.

Art. 79 Procedure at national level for dealing with AI systems presenting a risk

The national procedure for evaluation and measures (bringing into compliance, withdrawal, recall) with notification to the Commission and the other States.

Art. 80 Procedure for dealing with AI systems classified by the provider as non-high-risk in application of Annex III

The authority may review a system that escaped classification through the Article 6(3) filter and reclassify it as high-risk, with a fine for circumvention.

Art. 81 Union safeguard procedure

Disputes between States over measures are decided by the Commission.

Art. 82 Compliant AI systems which present a risk

Even a formally compliant system may present a risk to health, safety or fundamental rights; measures are then ordered as well.

Art. 83 Formal non-compliance

A missing CE marking, declaration, registration or representative is remedied, otherwise restriction or withdrawal from the market follows.

Art. 84 Union AI testing support structures

Horizontal technical support for supervision (Union testing capacity).

Remedies (Articles 85–87)

Art. 85 Right to lodge a complaint with a market surveillance authority

Anyone may lodge a complaint with the market surveillance authority, without prejudice to other remedies.

Art. 86 Right to explanation of individual decision-making

A person affected by a decision with legal or similarly significant effects that was taken on the basis of the output of a high-risk system from Annex III has the right to a clear and meaningful explanation of the system’s role and the main elements of the decision. The quiet relative of Article 22 GDPR, but aimed at the decision-making process rather than at data processing.

Art. 87 Reporting of infringements and protection of reporting persons

Reporting of infringements of the regulation is subject to the Whistleblowing Directive (EU) 2019/1937, in the Czech Republic therefore the Whistleblower Protection Act (zákon o ochraně oznamovatelů).

Enforcement against general-purpose models (Articles 88–94)

Art. 88 Enforcement of the obligations of providers of general-purpose AI models

An exclusive competence of the Commission, exercised through the AI Office.

Art. 89 Monitoring actions

The Office monitors compliance, and downstream providers may complain of infringements committed against them.

Art. 90 Alerts of systemic risks by the scientific panel

A qualified alert about systemic risk may trigger a model evaluation by the Commission.

Art. 91 Power to request documentation and information

The Commission requests documentation and further information from the model provider.

Art. 92 Power to conduct evaluations

The Commission may evaluate the model, including through independent experts, with access to the model via an API or other appropriate means.

Art. 93 Power to request measures

From mitigating risks, through restricting availability, to withdrawing the model from the market.

Art. 94 Procedural rights of economic operators of the general-purpose AI model

For model providers, procedural safeguards analogous to the market surveillance regime apply.

Chapter X · Articles 95–96

Codes of conduct and guidelines

The soft layer for everyone else.

Art. 95 Codes of conduct for voluntary application of specific requirements

Providers of systems outside high risk may voluntarily undertake selected requirements of Chapter III, plus elements such as sustainability, literacy, inclusive design or the participation of the groups affected.

Art. 96 Guidelines from the Commission on the implementation of this Regulation

The Commission issues practical guidelines, among other things on the requirements of Articles 8 to 15, on the Article 5 prohibitions, on Article 50, on the relationship to other legislation, and on the definition of an AI system, with regard to small and medium-sized enterprises. In practice they will often matter more than the text of the regulation itself.

Chapter XI · Articles 97–98

Delegation of power and committee procedure

Legislative machinery.

Art. 97 Exercise of the delegation

Delegation to the Commission (among other things to amend the annexes) for five years with tacit extension; the EP and the Council may veto an act.

Art. 98 Committee procedure

Standard comitology for implementing acts.

Chapter XII · Articles 99–101

Penalties

Three bands by severity, always the higher of a fixed sum and a percentage of turnover.

Art. 99 Penalties

Breach of the Article 5 prohibitions up to EUR 35 million or 7% of worldwide turnover. Breach of the other obligations (among them Articles 16, 25, 26, 50) up to EUR 15 million or 3%. False information to the authorities up to EUR 7.5 million or 1%. For small and medium-sized enterprises the lower of the two figures always applies, otherwise the higher. The States add their own enforcement regime.

Art. 100 Administrative fines on Union institutions, bodies, offices and agencies

For Union institutions and bodies, fines are imposed by the European Data Protection Supervisor, up to EUR 1.5 million for prohibited practices and up to EUR 750,000 for other breaches.

Art. 101 Fines for providers of general-purpose AI models

Imposed by the Commission, up to EUR 15 million or 3% of turnover, among other things for breaching Chapter V or failing to comply with measures under Article 93.

Chapter XIII · Articles 102–113

Final provisions

Amendments to sectoral legislation (AI in products is regulated inside the sectoral regimes, not on two tracks), transitional rules and phase-in.

Art. 102 Amendment to Regulation (EC) No 300/2008

An amendment to Regulation (EC) No 300/2008 on the protection of civil aviation. Implementing rules on AI-enabled security equipment are to take account of the requirements of Chapter III, Section 2.

Art. 103 Amendment to Regulation (EU) No 167/2013

An amendment to Regulation (EU) No 167/2013, the approval of agricultural and forestry vehicles, on the same logic of taking the requirements into account.

Art. 104 Amendment to Regulation (EU) No 168/2013

An amendment to Regulation (EU) No 168/2013, two- and three-wheel vehicles and quadricycles.

Art. 105 Amendment to Directive 2014/90/EU

An amendment to Directive 2014/90/EU on marine equipment.

Art. 106 Amendment to Directive (EU) 2016/797

An amendment to Directive (EU) 2016/797 on the interoperability of the rail system.

Art. 107 Amendment to Regulation (EU) 2018/858

An amendment to Regulation (EU) 2018/858 on the approval of motor vehicles.

Art. 108 Amendments to Regulation (EU) 2018/1139

Amendments to Regulation (EU) 2018/1139 on civil aviation (the EASA framework).

Art. 109 Amendment to Regulation (EU) 2019/2144

An amendment to Regulation (EU) 2019/2144 on vehicle safety requirements.

Art. 110 Amendment to Directive (EU) 2020/1828

A breach of the AI Act is added to the annex of Directive (EU) 2020/1828, so consumer organisations may bring representative actions for breaches of this regulation too. A key and overlooked track for private enforcement.

Art. 111 AI systems already placed on the market or put into service and general-purpose AI models already placed on the marked

A high-risk system placed on the market before the obligations took effect is brought into line only on a significant change to its design. Public authorities always bring theirs into line, at the latest by 2 August 2030. Large-scale EU information systems under Annex X placed before 2 August 2027 by 31 December 2030. General-purpose models placed before 2 August 2025 by 2 August 2027. A new paragraph 4, inserted by Regulation (EU) 2026/1744, gives generative systems placed on the market before 2 August 2026 until 2 December 2026 to comply with Article 50(2).

Art. 112 Evaluation and review

The Commission regularly assesses the need to amend the Annex III list and the prohibitions, and every four years evaluates the whole regulation and reports, including on the effectiveness of the penalties and the energy consumption of general-purpose models.

Art. 113 Entry into force and application

The staggered phase-in of the obligations; see the timeline on the AI Act card. The third paragraph was amended by Regulation (EU) 2026/1744, Article 1(40): Annex III from 2 December 2027, Annex I from 2 August 2028, the new Article 5 prohibitions from 2 December 2026 and Articles 102 to 110 from 27 July 2026.

Sources