Direct answers
Recognise your situation, see what applies
Every question below is a real-world situation. The answer shows what applies now, your first actions and the evidence to retain, assembled from the same versioned information model as the rest of the platform.
Prohibited practices and enforcement
- Does our AI use case fall under the prohibited practices?You want to be sure an existing or planned AI use case does not fall under the Article 5 prohibition, such as manipulation, social scoring or certain biometrics.
- What fines and enforcement does the AI Act have and who supervises?You want to know what can happen in case of non-compliance: which supervisors exist, what the fine ceilings are and which rules are already enforced.
Transparency, chatbots and content
- Our chatbot talks to customers. Does it have to say it is AI?An AI system interacting directly with people, such as a chatbot or voicebot in customer contact.
- We publish AI-generated content. Does it need labelling?Text, image, audio or video (partly) created with generative AI and published publicly.
- We create or use deepfakes or synthetic media. What is required?Image, audio or video of existing people, places or events generated or manipulated with AI.
- We build an AI product for customers. What are a provider’s duties?Your organisation develops an AI system (or has it developed) and places it on the market under its own name.
- What exactly does Article 50 of the AI Act regulate?You want the overview of the transparency obligations: which disclosure, marking or label applies to which AI scenario.
High risk and classification
- We use AI in recruitment and selection. Is that high risk?AI screening CVs, ranking candidates, targeting vacancies or analysing job interviews.
- We use AI for creditworthiness or insurance pricing. What applies?AI determining creditworthiness or credit scores, or risk and premium setting for life or health insurance.
- We use AI in education or assessment. Is that high risk?AI for admission, evaluation, level determination or exam proctoring in education or vocational training.
- We are considering facial recognition or other biometrics. Is that allowed?Biometric identification or categorisation of people, such as facial recognition for access or in public spaces.
- How do we set up an AI register and classify our systems?You want oversight: which AI systems run, who owns them, and which risk category applies per system.
- We use AI to monitor or evaluate employees. What applies?AI for task allocation, performance evaluation, promotion or termination decisions, or monitoring employee behaviour.
- What did the Digital Omnibus shift and what still applies as planned?You want the current timeline: which obligations were postponed and which deadlines stand.
- We use AI in healthcare. Which AI Act rules apply there?AI in a healthcare context, from triage and administrative support to AI in or around medical devices.
- How do we set up human oversight of AI?You want to know what the AI Act expects of human control over AI decisions: human in, on or over the loop, and who needs to be competent for it.
- What are a deployer’s obligations under Article 26?Your organisation uses (or will use) a supplier’s high-risk AI system and you want to know your own duties as deployer.
- Are we a provider or a deployer under the AI Act?You want to determine your organisation’s role per AI use case, because the role determines the duty list.
- Does our system fall under the definition of an AI system (Article 3)?You are unsure whether software, a computational model or a rule-based system legally qualifies as an AI system and thus falls under the regulation.
- What data requirements does the AI Act set for high-risk AI (Article 10)?You want to know which requirements apply to training, validation and test data and what you must be able to demonstrate about them.
- What technical documentation does the AI Act require (Article 11)?You want to know which file a high-risk AI provider must build and what you can request as a customer.
- Where do we start with AI Act compliance? A step-by-step approachYour organisation wants to become AI Act compliant but has no approach yet: you are looking for the logical order and a starting checklist.
- Do we need to register our AI system in the EU database?You want to know who must register in the EU database for high-risk AI and when that duty starts to apply.
- What does "reasonably foreseeable misuse" mean in the AI Act?You encounter the term in requirements and documentation and want to know what to do with it concretely in design and management.
- How do conformity assessment and CE marking work for AI?You want to know when an AI system needs a conformity assessment and CE marking and who performs it.
- What does the Article 9 risk management system require from us?You are the provider of a high-risk AI system and must show that you structurally identify, mitigate and keep tracking risks to health, safety and fundamental rights.
- How do we monitor our AI system after it goes live?Your high-risk system runs in production. You must keep tracking how it behaves in practice and act as soon as that behaviour deviates from what you established at assessment time.
- What instructions for use must we supply with our AI system?You supply a high-risk AI system to another organisation. They must be able to use it as you intended, which is only possible if you supply what the system can and cannot do.
- How accurate and robust does our AI system have to be?You want to know what performance level the regulation demands of a high-risk system, and how to demonstrate it when no statutory minimum percentage exists.
- We source AI from outside the EU. What do we need to arrange?You import, distribute or use an AI system from a provider established outside the Union, and want to know which duties land with you.
- What counts as high risk, and is our system one of them?You want to know whether your application falls into the regulation’s heaviest category, because nearly every further obligation depends on it.
AI literacy and organisation
- Our employees use ChatGPT or Copilot. What do we need to arrange?Employees use generative AI tools at work, with or without a formal policy.
- We want to draft an AI policy. Where do we start?Your organisation wants ground rules for responsible AI use: what is allowed, what is not, and who decides.
- What does Article 4 AI literacy concretely require from us?You want to know what the AI literacy duty entails and how to fulfil it demonstrably for your teams.
- What is automation bias and what should our organisation do about it?Employees blindly trust AI output. You want to know what the AI Act says about this and how to counter it demonstrably.
- Do we need to appoint an AI officer or AI compliance officer?You wonder whether the AI Act, like the GDPR with the DPO, requires a mandatory officer and how to assign AI responsibility if not.
- Is the ALTAI / trustworthy AI assessment mandatory under the AI Act?You know the Assessment List for Trustworthy AI and wonder how it relates to the legal duties.
- Who can help us implement the AI Act?You are looking for guidance: a workshop, training or a partner who executes the implementation with you rather than only advising.
- Does the AI Act also apply to small organisations?You are an SME, start-up or small institution and wonder whether this regulation applies to you or only to large technology companies.
Fundamental rights and public sector
- We are a public-sector organisation using AI. What needs to be in place?A municipality, executive agency or other public body using AI towards citizens, for example in benefits, enforcement or services.
- Do we need to perform a FRIA and how do we approach it?A fundamental rights impact assessment (Article 27) for deploying a high-risk AI system.
- How do the GDPR and the AI Act relate to each other?Your organisation is GDPR compliant and wants to know what the AI Act adds on top, and where DPIA and FRIA meet.
GPAI models
- We train or publish our own AI model. Which GPAI rules apply?A general-purpose AI model (foundation model, LLM) placed on the Union market, including open source.
- When does a GPAI model have systemic risk (the 10^25 FLOPs threshold)?You want to know when an AI model qualifies as GPAI with systemic risk and which additional duties then apply.
Situation not listed? Ask your question in the knowledge base or use the implementation map.