Direct answer
What does a provider actually have to do under the AI Act?
33 obligations under the AI Act bear on this, of which 14 apply today.
First step: Map every system to a point of Annex III.
The 33 obligations for a provider produce 3 concrete actions. Each action below belongs to a provision, carries its own conditions and names the date by which it has to be done. Likely role: provider of an ai system.
This applies now
- Article 111(2): legacy high-risk systems and the 2 August 2030 dateApplicable
- Article 4: AI literacyApplicable
- Articles 40 to 42: standards, common specifications and presumption of conformityApplicable
- Article 49: registration in the EU database before the system reaches the marketApplicable
- Article 4a: legal basis for bias testing with special categories of personal dataApplicable
- Article 5: prohibited practicesApplicable
- Article 50: transparencyApplicable
- Article 6(1a) to (1c): the tightened classification routeIn force
- Article 60: testing in real world conditions outside a sandboxApplicable
- Article 61: informed consent of test subjects for testing in real world conditionsApplicable
- Article 72: post-market monitoringApplicable
- Article 73: serious incident reportingApplicable
- Article 75: market surveillance, mutual assistance and the powers of the AI OfficeApplicable
- Articles 43-49: conformity assessment, CE and registrationApplicable
Coming up
- Annex III: the eight areas separatelyfrom 2 December 2027
- Annex III: high-risk AIfrom 2 December 2027
- Article 10: data and data governancefrom 2 December 2027
- Article 11: technical documentationfrom 2 December 2027
- Article 12: logging and traceabilityfrom 2 December 2027
- Article 13: transparency towards deployersfrom 2 December 2027
- Article 14: human oversightfrom 2 December 2027
- Article 15: accuracy, robustness and cybersecurityfrom 2 December 2027
- Article 16: the twelve duties of a provider of a high-risk AI systemfrom 2 December 2027
- Article 17: quality management systemfrom 2 December 2027
- Article 18: documentation keepingfrom 2 December 2027
- Article 20: corrective actions and duty of informationfrom 2 December 2027
- Article 21: cooperation with competent authoritiesfrom 2 December 2027
- Article 6(1): the product route to high riskfrom 2 August 2028
- Article 71: EU database for high-risk AI systems listed in Annex IIIfrom 2 December 2027
- Article 75(1a) and (1e): reporting to and assessment by the AI Officefrom 2 December 2027
- Article 8: compliance with the requirements for high-risk AI systemsfrom 2 December 2027
- Article 9: risk management systemfrom 2 December 2027
- Articles 22-25: value chain and authorised representativefrom 2 December 2027
What you have to do
- Map every system to a point of Annex III. Determine per AI system which of the eight areas and which lettered subpoint the intended purpose touches, or establish with reasons that no point applies. Then run the Article 6(3) test and record the outcome as Article 6(4) requires. Do so at the level of the intended purpose and not at the level of the department or the sector.
- Justify the Article 6(3) exception against each individual condition. Name which of the four Article 6(3) conditions you invoke, with facts, and separately justify why the system poses no significant risk of harm to health, safety or fundamental rights and does not materially influence the outcome of decision making.
- Set up data governance per dataset. Assess origin, representativeness, errors and completeness and examine possible bias with appropriate mitigation.
recruitment and selection
Candidate recommendation that automatically becomes a decision
An employer uses a system that ranks applicants and recommends a candidate to hire. In one setup a recruiter weighs that recommendation in their own assessment; in the other the outcome is applied automatically and a candidate is rejected without anyone looking at it.
Provenance: The Commission draft guidelines of 19 May 2026 address this case when determining whether an application falls under Annex III. The document is a consultation version: non-binding and not yet final.
Assess a recruitment system on its intended purpose rather than on whether a recruiter reviews the output, because adding or removing human involvement does not change its high-risk classification.
Draft guidelines on high-risk AI classification, 19 May 2026, annex on Annex III
AI articles on EU policy without substantive review
A website automatically publishes AI-generated articles about European policy. There is an editorial charter on paper, but nobody reviews the substance. Before publication only a spell check runs, and a second AI model reviews the text.
Provenance: The final Commission guidelines on Article 50 treat this case as a worked example under the transparency obligations. The document is non-binding.
An editorial charter on paper, a spell check and a second AI model do not count as human review, so without substantive fact checking by a person you must label the publication.
Commission Guidelines C(2026) 5054 final, 20.7.2026, worked examples under Article 50
AI summary of a council decision under editorial control
A news site places an AI-generated summary beneath a journalist's article about a recent town council decision. The editor in chief reads the summary on substance, checks the facts and signs off for publication.
Provenance: The final Commission guidelines on Article 50 treat this case as a worked example under the transparency obligations. The document is non-binding.
Do not rely on the editorial exception without substantive review by a competent person and a publicly identifiable holder of editorial responsibility, and note that any AI intervention after sign-off voids it.
Commission Guidelines C(2026) 5054 final, 20.7.2026, worked examples under Article 50
AI toy rewards children for dangerous challenges
A manufacturer markets an AI-powered toy that keeps children engaged by encouraging increasingly risky challenges, such as climbing furniture, exploring high shelves or handling sharp objects, in exchange for digital rewards and virtual praise.
Provenance: The Commission guidelines on prohibited AI practices treat this case as a worked example under Article 5. The document is non-binding: authoritative interpretation rests with the Court of Justice.
If children are among your users, assess every engagement and reward mechanism separately, because what counts as acceptable stimulation for adults can already be exploitation of children's curiosity and desire for rewards.
Commission Guidelines C(2025) 5052 final, 29.7.2025, worked examples under Article 5
No mandatory course format, no certificate, no exam and no AI officer
The Commission Q&A on AI literacy states that there is no one size fits all when it comes to AI literacy and that no strict requirements or mandatory trainings are imposed. On certification, the Q&A states literally that there is no need for a certificate and that organisations can keep an internal record of trainings or other guiding initiatives. On assessment, it states that Article 4 of the AI Act does not entail an obligation to measure the AI knowledge of employees. On governance, it states that no specific governance structure is mandated to comply with Article 4, so that unlike the data protection officer under the GDPR, no AI officer needs to be appointed. On the level, the Q&A states that following the Digital Omnibus amendment AI literacy remains an obligation for providers and deployers of AI systems, but that no specific or sufficient level is mandated and that the Regulation does not require guaranteeing any specific level of AI literacy of any individual. Against that, the Q&A states that simply relying on the AI systems' instructions for use or asking staff to read them might be ineffective, and that organisations should take into account general AI understanding within the organisation, whether they are a provider or a deployer, the risks associated with the systems deployed, staff knowledge gaps considering technical knowledge, experience, education and training, and contextual factors such as sector, purpose and affected populations. The Q&A further states that organisations may implement different levels of training or learning approaches depending on knowledge, experience, education and role, and that staff with a degree or experience in AI development are normally considered AI literate, while the organisation must still verify that those persons understand the specific AI systems of the organisation, know how to deal with them and are aware of all risks.
Commission Q&A on AI literacy, sections on required level, training formats, certificates, assessment of knowledge and governance structures (consulted 9 August 2026)
Article 4 reaches beyond your own staff, and the national supervisor enforces it
The Commission Q&A on AI literacy states that Article 4 applies to providers and deployers of AI systems and in addition to other persons dealing with the operation and use of AI systems on their behalf, covering persons broadly within the organisational remit, with a contractor, a service provider and a client given as examples. On clients, the Q&A states that they may need AI literacy depending on the specific risk, reasoning that affected persons should understand how decisions taken with the assistance of AI will have an impact on them. On geographic scope, the Q&A states that the AI Act's legal framework applies to both public and private actors inside and outside the EU as long as the AI system is placed on the Union market, used in the Union, or its use has an impact on people located in the EU. On supervision, the Q&A states that the supervision and enforcement of Article 4 is not with the AI Office but under the remit of national market surveillance authorities, and that supervision and enforcement began on 2 August 2026, while Article 4 itself entered into application on 2 February 2025. On sanctions, the Q&A states that national market surveillance authorities could impose penalties and other enforcement measures for infringements of Article 4, that this will be based on national laws that Member States were due to adopt by 2 August 2025, that any sanction must be proportionate and based on the individual case taking into account factors such as the nature and gravity of the infringement and its intentional or negligent character, and that sanctions are more likely if there is proof of an incident due to a lack of appropriate training and guidance. Article 4 is not listed in the enumeration in Article 99(4) of the AI Act, which covers only Articles 16, 22, 23, 24, 26, 31, 33(1), (3) and (4), 34 and 50, so the level of any penalty for Article 4 follows from national law rather than from the Regulation's own ceilings. The Q&A further states that Article 4 reinforces the transparency provisions of Article 13 and the human oversight provisions of Article 14 and indirectly contributes to the protection of affected persons, and that for deployers of high-risk systems the Article 26 obligation to ensure staff are trained to ensure human oversight is a distinct requirement; that requirement becomes applicable on 2 December 2027 for standalone Annex III systems and on 2 August 2028 for Annex I systems.
Commission Q&A on AI literacy, sections on target groups, geographic scope, supervision and enforcement, and sanctions (consulted 9 August 2026)
AI agents must disclose both their AI nature and on whose behalf they act
Point (31) of the guidelines of 20 July 2026 states that AI agents are covered by Article 50(1) if they are capable of interacting with the persons instructing them or with other natural persons in the execution of their tasks, citing as examples making bookings, managing correspondence, negotiating or concluding contracts and executing purchases. That same point requires AI agents to be designed and developed so that they disclose both their artificial nature and the person on whose behalf they are acting, given the need for transparency of the origin and of the delegation of authority and accountability for the consequences of their actions. This also applies in complex multi-agent architectures in which other agents interact directly with natural persons. Where the provider cannot reliably determine before placing on the market or putting into service whether the agent will directly interact with a natural person, the agent should be designed at the architecture level and instructed to disclose itself in every situation where it is reasonably likely to interact with a natural person, including where that person represents a legal entity. Agents should also disclose themselves to the persons instructing them at key steps such as authorisation, reporting and validation, including where the agent receives, processes or relies upon outputs generated by other AI systems rather than by a natural person, and at every new interaction. Point (63) adds that Article 50(2) may apply to AI agents where the agent takes an action whose output is AI-generated or manipulated content perceptible by natural persons, while intermediate processing steps such as reasoning and chain of thought and non-perceptible actions such as a web request or browser action fall outside that scope.
Commission Guidelines C(2026) 5054 final, Section 3.1.1 point (31) and Section 4.1.2 point (63)
Artistic or satirical work is not exempt but attenuated, and the informative character always prevails
Point (119) of the guidelines of 20 July 2026 describes an attenuated transparency obligation for deep fakes forming part of evidently artistic, creative, satirical, fictional or analogous works or programmes, where the obligation is limited to disclosure in an appropriate manner that does not hamper the display or enjoyment of the work. Point (120) describes the categories: artistic works are created for the purpose of art, including music, cinematographic works and visual arts; creative works involve creative choices, while works mainly motivated by functional or technical considerations cannot be regarded as creative; satirical works are intended to criticise society, politics, business or public figures through humoristic techniques; fictional works involve persons, objects, places, entities or events in an imaginary but verisimilitude setting; analogous works share core traits with those categories without fitting neatly into one. Point (122) states that it must be evident to the natural persons exposed to it that the content falls within one of those categories, that the categories must therefore be interpreted strictly given the lighter disclosure regime and the interests of freedom of expression and freedom of the arts and sciences, and that content whose nature is potentially unclear or ambiguous to the audience falls outside this lighter regime. Relevant factors, per that same point, are whether the content displays formats or styles characteristic of the category, the context in which it is presented, and audience expectations. That same point excludes content whose nature is exclusively informative or commercial and recognisable as such, citing news reporting, notes that advertisements or documentaries may be regarded as evidently creative or fictional in certain specific situations but not in others because the assessment is case-specific, and states that where the deep fake combines multiple characters, for example informative and creative, the informative character should always prevail and the standard labelling requirements apply. Point (123) stresses that these deep fakes are not excluded from the obligation: the deployer must still disclose the AI origin or manipulation, but may do so in an appropriate manner, and must in any case comply with Article 50(5). Point (124) states that reliance on the attenuated obligation cannot justify failing to respect the fundamental rights of individuals or the rights of rightsholders under Union intellectual property or data protection law. As examples within the categories the document cites movies featuring AI de-aged existing actors or digital replicas of deceased actors, AI-generated music in the style of existing artists, and an AI-manipulated image of an existing politician in a scene clearly meant as humorous criticism. Outside the categories the document places among others an AI-manipulated video in the style of a teleshopping channel, AI-generated images of celebrities implying involvement in activities that never happened, and an AI-manipulated video featuring a realistic synthetic influencer focused solely on displaying a sponsored product's functionalities.
Commission Guidelines C(2026) 5054 final, Section 6.1.3, points (119) to (124) and the accompanying example lists
EN 18286:2026: quality management system for EU AI Act regulatory purposes
EN 18286:2026 (Artificial intelligence: Quality management system for EU AI Act regulatory purposes) was drafted by CEN/CLC/JTC 21 under standardisation request M/613 and approved by CEN-CENELEC on 12 July 2026. It is the first JTC 21 deliverable to reach publication. According to a published coverage statement accompanying the standard, not yet confirmed by a second independent source, it addresses Article 17(1) points (a) to (m) and Article 11(1) first sentence, and expressly not Article 17(2) to (4) or Article 72. The standard is NOT currently cited in the Official Journal. The Article 40 presumption of conformity only attaches after that citation.
EN ISO/IEC 42001: artificial intelligence management system
ISO/IEC 42001:2023 is the first certifiable international standard for an AI management system, published on 18 December 2023 and structured on the plan-do-check-act cycle. The text was adopted unchanged as EN ISO/IEC 42001:2026, approved by CEN on 13 March 2026, with national implementation by the member standards bodies. This adoption is not a deliverable under standardisation request M/613: the standard is not cited in the Official Journal and therefore confers no presumption of conformity under Article 40. For Article 17, the designated deliverable under M/613 is EN 18286:2026; that standard is likewise not cited in the Official Journal.
ISO/IEC 12792: transparency taxonomy of AI systems
ISO/IEC 12792:2025 (Information technology: Artificial intelligence: Transparency taxonomy of AI systems) was published in November 2025 by ISO/IEC JTC 1/SC 42. It specifies a taxonomy of information elements to help stakeholders identify and address transparency needs, and describes the semantics of those elements and their relevance to different stakeholders' objectives. The text was adopted as a European standard as EN ISO/IEC 12792:2025. It is not cited in the Official Journal and therefore confers no presumption of conformity under Article 40. For Article 13 the designated deliverable is prEN 18229-3.
ISO/IEC 23894: guidance on risk management for AI
ISO/IEC 23894:2023 (Information technology: Artificial intelligence: Guidance on risk management) was published in February 2023 and is the first international standard dealing specifically with risk management for AI. It is non-prescriptive and built on the ISO 31000 structure. The text was adopted by CEN-CENELEC as EN ISO/IEC 23894:2024. It is not cited in the Official Journal and therefore confers no presumption of conformity under Article 40 of the AI Act. The deliverable intended to do so for Article 9 is prEN 18228.
- Annex III, point 1: biometrics
- Annex III, point 1, as that point stands in the Regulation, with its lettered subpoints and the exceptions named in them.
- Annex III, point 2: critical infrastructure
- Annex III, point 2, as that point stands in the Regulation, with its lettered subpoints and the exceptions named in them.
- Annex III, point 3: education and vocational training
- Annex III, point 3, as that point stands in the Regulation, with its lettered subpoints and the exceptions named in them.
- Annex III, point 4: employment and workers management
- Annex III, point 4, as that point stands in the Regulation, with its lettered subpoints and the exceptions named in them.
General interpretation, not legal advice. Checked against Regulation (EU) 2024/1689 and the Digital Omnibus (EU) 2026/1744; the official source remains authoritative.
Full map for your situation