Direct answer
When are you a provider under the AI Act?
33 obligations under the AI Act bear on this, of which 14 apply today.
First step: Map every system to a point of Annex III.
Whether you are a provider is not a matter of what you call yourself but of what you do with the system. Across the 33 obligations there are 96 conditions and exceptions that decide it. Below they are listed per provision, with the official source. Likely role: provider of an ai system.
This applies now
- Article 111(2): legacy high-risk systems and the 2 August 2030 dateApplicable
- Article 4: AI literacyApplicable
- Articles 40 to 42: standards, common specifications and presumption of conformityApplicable
- Article 49: registration in the EU database before the system reaches the marketApplicable
- Article 4a: legal basis for bias testing with special categories of personal dataApplicable
- Article 5: prohibited practicesApplicable
- Article 50: transparencyApplicable
- Article 6(1a) to (1c): the tightened classification routeIn force
- Article 60: testing in real world conditions outside a sandboxApplicable
- Article 61: informed consent of test subjects for testing in real world conditionsApplicable
- Article 72: post-market monitoringApplicable
- Article 73: serious incident reportingApplicable
- Article 75: market surveillance, mutual assistance and the powers of the AI OfficeApplicable
- Articles 43-49: conformity assessment, CE and registrationApplicable
Coming up
- Annex III: the eight areas separatelyfrom 2 December 2027
- Annex III: high-risk AIfrom 2 December 2027
- Article 10: data and data governancefrom 2 December 2027
- Article 11: technical documentationfrom 2 December 2027
- Article 12: logging and traceabilityfrom 2 December 2027
- Article 13: transparency towards deployersfrom 2 December 2027
- Article 14: human oversightfrom 2 December 2027
- Article 15: accuracy, robustness and cybersecurityfrom 2 December 2027
- Article 16: the twelve duties of a provider of a high-risk AI systemfrom 2 December 2027
- Article 17: quality management systemfrom 2 December 2027
- Article 18: documentation keepingfrom 2 December 2027
- Article 20: corrective actions and duty of informationfrom 2 December 2027
- Article 21: cooperation with competent authoritiesfrom 2 December 2027
- Article 6(1): the product route to high riskfrom 2 August 2028
- Article 71: EU database for high-risk AI systems listed in Annex IIIfrom 2 December 2027
- Article 75(1a) and (1e): reporting to and assessment by the AI Officefrom 2 December 2027
- Article 8: compliance with the requirements for high-risk AI systemsfrom 2 December 2027
- Article 9: risk management systemfrom 2 December 2027
- Articles 22-25: value chain and authorised representativefrom 2 December 2027
What decides whether this is about you
- Applies when: Applies where the intended purpose of the AI system falls within one of the eight areas listed in Annex III: biometrics, critical infrastructure, education and vocational training, employment and workers management, access to essential private and public services, law enforcement, migration and border control management, or administration of justice and democratic processes.
- Applies when: Classification follows Article 6(2). For points 1, 6 and 7 the text adds the condition that the use is permitted under relevant Union or national law. We read that condition as meaning that a prohibition under Article 5 comes before the question whether the system is high-risk; that is our reading and not the literal text, which states the condition without naming the order.
- Applies when: The duty rests on the provider, but the role can shift. Under Article 25(1) a distributor, importer, deployer or third party becomes a provider itself where it puts its name or trademark on the system, makes a substantial modification, or changes the intended purpose such that the system becomes high-risk under Article 6. From that moment it carries the mapping to a point of Annex III itself.
- Unless: Article 6(3) takes a system listed in Annex III back outside high-risk where it does not pose a significant risk of harm to health, safety or fundamental rights, including by not materially influencing the outcome of decision making, and one of four conditions is met: the system performs a narrow procedural task, it improves the result of a previously completed human activity, it detects decision making patterns or deviations from prior patterns without replacing or influencing the previously completed human assessment without proper human review, or it performs a preparatory task to an assessment relevant for the purposes of the use cases listed in Annex III. A system that performs profiling of natural persons is always high-risk.
- Unless: The derogation is not free. Article 6(4) requires a provider who considers that a system referred to in Annex III is not high-risk to document its assessment before the system is placed on the market or put into service, subjects that provider to the registration obligation in Article 49(2), and requires it to provide the documentation to national competent authorities on request.
- Applies when: The intended purpose falls within a use case listed in Annex III.
- Applies when: Classification follows Article 6(2).
- Unless: A listed Annex III system may fall outside high-risk under the strict conditions in Article 6(3), except where it profiles. The assessment and registration must be documented.
- Applies when: The high-risk system is trained with data; the provider composes the datasets, the deployer controls relevant input data.
- Unless: For special categories of personal data the strict exception of Article 10(5) applies (bias detection and correction under conditions).
- Applies when: The provider places a high-risk AI system on the market or puts it into service.
- Unless: Small providers (SMEs) may provide the documentation in the simplified form established by the Commission.
- Applies when: The transitional rule is without prejudice to the application of Article 5, as referred to in Article 113, third paragraph, point (a). A prohibited practice remains prohibited, regardless of when the system was placed on the market or put into service and regardless of whether the design has changed.
- Applies when: The transitional rule concerns the high-risk requirements of Chapter III and is not an exemption from the whole Regulation. Article 4 has applied since 2 February 2025 irrespective of when a system reached the market, and Article 50 has applied to all systems in scope since 2 August 2026. The paragraph 4 added by the Digital Omnibus confirms this: it gives legacy generative systems a short extra period for Article 50(2), which would make no sense if Article 50 did not reach them.
- Applies when: Applies to operators of high-risk AI systems placed on the market or put into service before the date of application of Chapter III referred to in Article 113, other than the systems referred to in paragraph 1 that are components of the large-scale IT systems listed in Annex X. That date is 2 December 2027 for systems that are high-risk under Article 6(2) and Annex III, and 2 August 2028 for systems that are high-risk under Article 6(1) and Annex I. For that group the high-risk requirements bite only once the systems are subject to significant changes in their designs as from that date.
- Applies when: The grace period runs per type and model, not per unit. If at least one individual unit of the type and model was lawfully placed on the market or put into service before the cut off date, other units of the same type and model are covered too and may be offered without additional obligations, requirements or additional certification, as long as the design remains unchanged. The decisive date is the one on which the first unit of that type and model was placed on the market or put into service in the Union.
- Applies when: Applies independently to providers and deployers of high-risk AI systems intended to be used by public authorities. They must in any case take the necessary steps to comply with the requirements and obligations of the Regulation by 2 August 2030, even where the design remains unchanged.
- Unless: Systems that are components of the large-scale IT systems established by the legal acts listed in Annex X fall not under paragraph 2 but under paragraph 1. Paragraph 1 was not amended by the Digital Omnibus and keeps its own cut off: placed on the market or put into service before 2 August 2027, with compliance by 31 December 2030.
- Applies when: The system is high-risk; the provider designs the logging, provider and deployer retain the logs under their control.
- Unless: The retention period may be limited by Union or national law, including data protection.
- Applies when: The provider supplies a high-risk system; the deployer uses it according to the instructions.
- Unless: The level of detail may match the intended deployer’s knowledge; trade secrets need not be disclosed.
- Applies when: The system is high-risk; the provider builds in oversight measures, the deployer assigns oversight to competent persons.
- Unless: For remote biometric identification the reinforced requirement of verification by at least two authorised persons applies (Article 14(5)), with the exceptions listed there.
- Applies when: The provider places a high-risk AI system on the market or puts it into service.
- Unless: Systems that continue learning after deployment carry additional requirements to control feedback loops and drift.
- Applies when: Applies to providers of high-risk AI systems. For the standalone Annex III route (Article 6(2)) the date is 2 December 2027. For systems embedded as a safety component in products covered by the Annex I harmonisation legislation (Article 6(1)) the date is 2 August 2028.
- Unless: A provider that considers an Annex III system not to be high-risk must document that assessment before placing it on the market and remains subject to the registration obligation of Article 49(2) (Article 6(4)). Where an AI system referred to in Annex III performs profiling of natural persons it is always considered high-risk (Article 6(3), final subparagraph).
- Applies when: The provider places high-risk AI systems on the market or puts them into service.
- Unless: Providers already under sectoral quality regimes may integrate the AI elements into that existing system; SMEs may implement elements in simplified form.
- Applies when: Applies to the provider of a high-risk AI system. The period ends ten years after the system has been placed on the market or put into service.
- Applies when: Where the provider is a financial institution subject to requirements regarding internal governance, arrangements or processes under Union financial services law, it maintains the technical documentation of point (a) as part of the documentation it already keeps under that law. That is not an exemption from the retention duty but an indication of the regime in which it is carried out for that one component. Paragraph 3 does not mention points (b) to (e).
- Applies when: Applies to providers of high-risk AI systems as soon as they consider, or have reason to consider, that a system they have placed on the market or put into service is not in conformity with this Regulation. For the standalone Annex III route (Article 6(2)) the date is 2 December 2027. For systems embedded as a safety component in products covered by the Annex I harmonisation legislation (Article 6(1)) the date is 2 August 2028.
- Applies when: The second layer in paragraph 2 is added only where the system presents a risk within the meaning of Article 79(1) and the provider becomes aware of that risk. The investigation of causes and the duty to inform the market surveillance authorities and, where applicable, the notified body that issued a certificate under Article 44, then come on top of the corrective actions under paragraph 1.
- Applies when: The distributor, the importer and the deployer appear here as affected parties, but that is not their only possible position. Anyone who puts their name or trade mark on a high-risk system already placed on the market, who substantially modifies such a system, or who changes the intended purpose of a system not classified as high-risk so that it becomes high-risk, is considered a provider under Article 25(1) and is subject to the obligations of Article 16. Point (j) of that Article routes straight to Article 20, so this provision then becomes a duty of their own rather than a notification arriving from someone else. In the trade mark case this applies without prejudice to contractual arrangements allocating the obligations otherwise.
- Unless: Article 20 is by definition about systems already placed on the market or put into service, and that is exactly the group covered by the transitional rule of Article 111(2). That provision was replaced by Article 1, point (39)(a), of Regulation (EU) 2026/1744 and now reads: without prejudice to the application of Article 5 as referred to in Article 113, third paragraph, point (a), this Regulation applies to operators of high-risk AI systems, other than the systems referred to in paragraph 1 of that Article, that have been placed on the market or put into service before the date of application of Chapter III referred to in Article 113, only if, as from that date, those systems are subject to significant changes in their designs. The cut-off is therefore no longer a fixed date in paragraph 2: the date of 2 August 2026 that stood there until that amendment has been removed, and the amended paragraph names no date of its own. The carve-out in paragraph 1 covers systems that are components of the large-scale IT systems listed in Annex X; paragraph 1 was not amended and keeps a cut-off of its own. For systems intended to be used by public authorities the reprieve in paragraph 2 does not hold: there, compliance with the requirements and obligations is due by 2 August 2030 in any event. Which date of application of Chapter III is the cut-off is an open point: the object on Article 111 reads it as route dependent, so 2 December 2027 for the Annex III route and 2 August 2028 for the Annex I route, and marks that reading expressly as preliminary. That question is carried there, not here.
- Applies when: Applies to providers of high-risk AI systems as soon as a competent authority makes a reasoned request. For the standalone Annex III route (Article 6(2)) the date is 2 December 2027. For systems that are high-risk under Article 6(1) and relate to products covered by Annex I, Section A, the date is 2 August 2028. For products covered by Annex I, Section B, Article 21 does not apply at all: amended Article 2(2) makes only Article 6(1), Article 60a and Articles 102 to 112 applicable there, and Article 21 is not on that list. That is not a corner case, because the Machinery Regulation (EU) 2023/1230 has been moved from Section A to Section B. Note also the new Article 2(13): for systems under Annex I, Section A, the Commission may limit the application of Articles 17 to 25, and therefore of Article 21, by delegated act.
- Applies when: For systems already running, the amended Article 111(2) applies: without prejudice to the application of Article 5 as referred to in Article 113, third paragraph, point (a), the Regulation applies to operators of high-risk AI systems, other than those referred to in Article 111(1), placed on the market or put into service before the date of application of Chapter III referred to in Article 113, only if, as from that date, those systems are subject to significant changes in their designs. The reference date is therefore no longer 2 August 2026 but whichever date applies to the system: 2 December 2027 for the Annex III route and 2 August 2028 for the Annex I route. For systems intended to be used by public authorities the date of 2 August 2030 applies in any case.
- Applies when: What the authority obtains pursuant to this Article is treated in accordance with the confidentiality obligations of Article 78. That is not a limit on the duty to supply and therefore not an exception: it is how what you supplied is handled on the receiving side.
- Unless: Paragraph 2 carries two limits, not one. Access to the automatically generated logs applies "as applicable", and it applies "to the extent such logs are under their control". Logs held solely by the deployer therefore fall outside what the provider can supply under this Article; the deployer keeps those logs itself under Article 26(6).
- Applies when: The organisation is a provider or deployer of an AI system within scope.
- Unless: The provision does not require a specific individual level to be guaranteed.
- Applies when: The presumption in Article 40(1) arises only where the references of the harmonised standard have been published in the Official Journal of the European Union in accordance with Regulation (EU) No 1025/2012, and it reaches only to the extent that those standards cover those requirements or obligations. The same holds for the cybersecurity certification of Article 42(2), the references of which must likewise have been published in the Official Journal.
- Applies when: The justification duty of Article 41(5) arises only where a common specification has actually been established by implementing act for the requirement concerned and the provider does not apply it. Where no such specification exists, there is nothing to depart from and you demonstrate conformity by the ordinary route.
- Unless: A presumption of conformity is not a finding of compliance. The text says the system shall be presumed to be in conformity, and only in so far as the standard or the specification covers the requirements or obligations concerned. Outside that coverage the burden of proof rests fully on the provider, and a market surveillance authority can rebut the presumption where the system in fact does not meet the requirements.
- Unless: Article 41(4) makes a common specification lapse as soon as the standard exists: when reference to a harmonised standard is published in the Official Journal of the European Union, the Commission repeals the implementing acts, or parts thereof, which cover the same requirements or obligations. A file leaning on a repealed specification thereby loses its basis.
- Applies when: Paragraph 4 does not except the registration but relocates it: for the systems referred to in points 1, 6 and 7 of Annex III in the areas of law enforcement, migration, asylum and border control management, the registration referred to in paragraphs 1, 2 and 3 goes into a secure non-public section of the EU database, with a limited list of fields from Annex VIII and Annex IX, and only the Commission and the national authorities referred to in Article 74(8) have access to it.
- Applies when: Applies where a provider or, where applicable, an authorised representative places on the market or puts into service a high-risk AI system listed in Annex III, and where that same party places on the market or puts into service an AI system for which it has concluded that it is not high-risk according to Article 6(3).
- Applies when: Applies where a deployer that is a public authority, Union institution, body, office or agency, or a person acting on their behalf, puts into service or uses a high-risk AI system listed in Annex III.
- Applies when: Registration is a precondition and not a notification afterwards: paragraphs 1 and 2 attach to the moment before the system is placed on the market or put into service, paragraph 3 to the moment before it is put into service or used.
- Unless: This is an exception to the route and not to the duty. Paragraphs 1 and 3 except the high-risk AI systems referred to in point 2 of Annex III from registration in the EU database, and paragraph 5 provides that those systems are registered at national level. For critical infrastructure the registration therefore does not fall away: it runs through the national register rather than through the Article 71 EU database.
- Applies when: Paragraph 1 is open only to the provider of a high-risk AI system, and only to the extent that the processing is strictly necessary to detect and correct bias in accordance with Article 10(2), points (f) and (g). The deployer cannot rely on this paragraph, not even for a high-risk system; for the deployer the route runs through paragraph 2.
- Applies when: Paragraph 2 is open to providers and deployers of other AI systems and models and to deployers of high-risk AI systems, but carries its own substantive threshold: the processing must be strictly necessary in view of possible biases that are likely to affect the health and safety of persons, have a negative impact on fundamental rights or lead to discrimination prohibited under Union law, especially where data outputs influence inputs for future operations. Bias without one of those consequences falls outside it.
- Applies when: The six conditions in paragraph 1 are cumulative and, through paragraph 2, point (b), apply to the wider circle as well: (a) other data, including synthetic or anonymised data, demonstrably do not suffice; (b) technical limitations on re-use apply plus state of the art security and privacy preserving measures, including pseudonymisation; (c) there is strict access control with documentation and confidentiality; (d) the data are not transmitted, transferred or otherwise accessed by other parties; (e) they are deleted once the bias has been corrected or the retention period ends, whichever comes first; (f) the record of processing activities states why the processing was strictly necessary and why the objective could not be achieved with other data.
- Unless: Paragraph 2 closes by providing that it creates no obligation to carry out bias detection and correction. Article 4a is therefore a basis and not an instruction: without carrying out such processing there is nothing to comply with under this article, there is no date by which anything must be done, and outside the purpose of bias detection and correction it grants no room at all.
- Applies when: Placing on the market, putting into service or using AI falls under one of the practices in Article 5(1), including harmful manipulation or exploitation of vulnerabilities, social scoring, predicting criminal offences based on profiling, untargeted scraping of facial images, emotion recognition in the workplace or education, biometric categorisation by sensitive characteristics and real-time remote biometric identification in publicly accessible spaces for law enforcement.
- Unless: The exceptions are narrow: among others, emotion recognition for medical or safety reasons, and the exhaustively defined law-enforcement situations with authorisation for real-time remote biometric identification in Article 5(2) to (7). The exception must be established and documented in advance.
- Applies when: An AI system is intended to interact directly with natural persons.
- Applies when: The system generates or manipulates synthetic audio, image, video or text, or the use concerns a specifically listed deployer scenario.
- Unless: The direct-interaction disclosure is not required where this is obvious to a reasonably well-informed, observant and circumspect person, considering circumstances and context.
- Unless: Only Article 50(2) has a transition until 2 December 2026 for systems placed on the market before 2 August 2026.
- Applies when: The AI system is intended to be used as a safety component of a product, or the AI system is itself a product, covered by the Union harmonisation legislation listed in Annex I. Whether the system is placed on the market independently of that product is irrelevant.
- Applies when: That product, or the AI system as a product itself, is required under that same harmonisation legislation to undergo a third-party conformity assessment with a view to its placing on the market or putting into service. Both conditions must be fulfilled together.
- Unless: Article 6(1a), inserted by Regulation (EU) 2026/1744, provides that AI systems solely used for non-safety related aspects of user assistance, performance optimisation, service efficiency, automation or convenience or quality control do not qualify as safety components. Paragraph 1b takes that exclusion back as soon as failure or malfunctioning would endanger health and safety.
- Unless: Article 6(1c), as inserted, provides that a product required to undergo a third-party conformity assessment solely due to risks other than risks to health and safety, in particular risks relating to the distribution of radio spectrum or electromagnetic interference that do not affect health and safety, is not considered to fulfil the condition in paragraph 1, point (b).
- Applies when: Applies where it must be determined whether an AI system is intended to be used as a safety component of a product, or is itself a product, covered by the Union harmonisation legislation listed in Annex I, and whether that product is required to undergo a third-party conformity assessment. Because paragraph 1a writes itself for the purposes of this Regulation, the delimitation also bears on Annex III, point 2, where the notion of safety component is used for critical digital infrastructure, road traffic and the supply of water, gas, heating or electricity.
- Applies when: For the consequences under Chapter III only Annex I, Section A, counts. For products under Section B, including machinery since Regulation (EU) 2023/1230 was moved there, the amended Article 2(2) means that only Article 6(1), Article 60a and Articles 102 to 112 apply.
- Unless: Paragraph 1a provides that AI systems solely used for non-safety related aspects of user assistance, performance optimisation, service efficiency, automation or convenience or quality control do not qualify as safety components. Paragraph 1b takes that exclusion back: AI systems the failure or malfunctioning of which would endanger health and safety do qualify as safety components.
- Unless: Paragraph 1c provides that a product required to undergo a third-party conformity assessment solely due to risks other than risks to health and safety, in particular risks relating to the distribution of radio spectrum or electromagnetic interference that do not affect health and safety, is not considered as fulfilling the condition in paragraph 1, point (b).
- Applies when: Applies where you are a provider or prospective provider of an Annex III high-risk AI system and you want to test it in real world conditions outside an AI regulatory sandbox, before placing it on the market or putting it into service. If you are established outside the Union, Article 60(4), point (d), requires you to appoint a legal representative established in the Union; that is a different figure from the authorised representative under Article 22.
- Unless: Article 60(1), third subparagraph, leaves Union and national law on real-world testing of high-risk systems related to products under the Annex I harmonisation legislation unaffected. Article 60(4), point (i), contains a law enforcement carve-out: where seeking informed consent would prevent the system from being tested, testing may proceed without consent, provided the testing and its outcome have no negative effect on the subjects and their personal data are deleted after the test. For the systems referred to in Annex III, points 1, 6 and 7, in law enforcement, migration, asylum and border control, registration runs through the secure non-public section of the EU database under Article 49(4), point (d). For the systems referred to in Annex III, point 2, Article 49(5) requires registration at national level.
- Applies when: Applies for the purpose of testing in real world conditions under Article 60, that is where you are a provider or prospective provider of a high-risk AI system listed in Annex III and you test that system in real world conditions outside an AI regulatory sandbox. Article 60(4), point (i), makes informed consent in accordance with Article 61 one of the cumulative conditions under which such testing is allowed. Consent is obtained per subject prior to their participation. Article 61 sits in Chapter VI, which is named in none of the three exceptions in the third paragraph of Article 113; the general date of application in the second paragraph therefore governs, 2 August 2026.
- Applies when: If under Article 60(2) you test in partnership with one or more deployers or prospective deployers, the condition stays with you as the provider, even where that party is the one in contact with the subject. Article 60(4), point (h), requires you and that party to conclude an agreement specifying your tasks and responsibilities; that is where you record who informs, who obtains the consent and who keeps the file.
- Unless: The only exception sits not in Article 61 but in Article 60(4), point (i): in the case of law enforcement, where seeking informed consent would prevent the AI system from being tested in real world conditions, testing may proceed without that consent, provided the testing and its outcome have no negative effect on the subjects and their personal data are deleted after the test is performed. Outside that context there is no exception to consent; Article 61 contains none of its own.
- Applies when: Applies where a provider or authorised representative places an Annex III high-risk AI system on the market or puts it into service and registers itself and that system in accordance with Article 49, where that same party registers a system considered not to be high-risk pursuant to Article 6(3), or where a deployer that is, or that acts on behalf of, a public authority, agency or body registers itself, selects the system and registers its use.
- Unless: Article 49(5) provides that high-risk AI systems referred to in point 2 of Annex III are registered at national level. For those systems the registration therefore does not run through the Article 71 EU database.
- Unless: Paragraph 4 excludes the section referred to in Article 49(4) from public availability. For the systems referred to in points 1, 6 and 7 of Annex III in the areas of law enforcement, migration, asylum and border control management, registration takes place in a secure non-public section of the database, with fewer fields than the full Sections: Section A, points 1 to 10 with the exception of points 6, 8 and 9; Section B, points 1 to 5 and points 8 and 9; Section C, points 1, 2 and 3; and points 1, 2, 3 and 5 of Annex IX. Only the Commission and the national authorities referred to in Article 74(8) have access to those sections. Mind the cross-reference: Article 49(4) was not amended by Regulation (EU) 2026/1744 and therefore still names point 9 of Section B, while Article 1, point (42), of that same Regulation deleted that point. There is nothing left to fill in there.
- Unless: Paragraph 4 additionally excludes the section referred to in Article 60(4), point (c). The main rule there is not a secure section: the provider or prospective provider registers the testing in real world conditions in accordance with Article 71(4), with a Union wide unique single identification number and the information specified in Annex IX. Under the third sentence of paragraph 4 that information is accessible only to market surveillance authorities and the Commission, unless the provider or prospective provider has given consent for also making it accessible to the public. Only for points 1, 6 and 7 of Annex III does the testing registration go into the secure non-public section under Article 49(4), point (d), and for point 2 of Annex III to national level under Article 49(5).
- Applies when: The provider has a high-risk system on the market; deployers supply the real-world data via monitoring and signals.
- Unless: The plan may be proportionate to the nature of the system and align with existing sectoral monitoring regimes.
- Applies when: A serious incident occurs with a high-risk system: death or serious harm to health, serious and irreversible disruption of critical infrastructure, infringement of fundamental-rights protections or serious damage to property or environment.
- Unless: For systems under sectoral reporting regimes with equivalent duties, reporting may run through that regime to avoid duplication.
- Applies when: Applies to providers of AI systems that fall under the competence of the AI Office pursuant to Article 75(1) and that are classified as high-risk. The replaced paragraph 1 carries two independent routes, and the four carve-outs at (i) to (iv) sit inside point (a) alone. Along point (a) Annex I systems fall outside the competence, as do point 2 of Annex III and point 8 as regards the administration of justice; point 8(b), on influencing elections and referenda, is not carved out. Point (b) is a route of its own: a system that constitutes, or is integrated into, a designated very large online platform or very large online search engine falls under the competence of the AI Office even where one of the carve-outs in point (a) applies. Anyone testing point (a) alone places such a system outside this obligation wrongly. Those duties start to apply when Chapter III, Sections 1 to 3, becomes applicable, and that date depends on the route: 2 December 2027 for the route of Article 6(2) and Annex III, and 2 August 2028 for the route of Article 6(1) and Annex I, which point (b) can bring into view. The deadline_at field carries the earlier of the two.
- Applies when: Applies to AI systems based on a general-purpose AI model where the model and the system are developed by the same provider or by providers forming part of the same undertaking, and to AI systems that constitute or are integrated into a very large online platform or very large online search engine designated in accordance with Regulation (EU) 2022/2065. The exclusive competence applies to the providers of those systems, and to deployers only where they are also the provider or form part of the same undertaking as the provider.
- Applies when: The allocation of competence itself operates from 2 August 2026, because Article 75 sits in Chapter IX. It covers the obligations that apply at that moment, such as the prohibition in Article 5, the transparency duties of Article 50 and the obligations for general-purpose AI models. The two literal duties the amending regulation places on the provider, the reporting route of paragraph 1a and the fees of paragraph 1e, attach to high-risk status and therefore follow 2 December 2027; they sit in the separate object article-75-ai-office-high-risk-duties.
- Unless: Paragraph 1, point (a) carves four groups out of the exclusive competence of the AI Office: AI systems related to products covered by the Union harmonisation legislation listed in Annex I, systems referred to in point 2 of Annex III, systems provided by law enforcement authorities, border management authorities and financial institutions insofar as they fall under Article 74(6), and systems referred to in point 8 of Annex III as regards the administration of justice. Who is competent instead differs per group and is not always "the market surveillance authority": for financial institutions Article 74(6) points to the national authority responsible for their financial supervision, and for law enforcement, border management and the administration of justice Article 74(8) has the Member State designate either the data protection supervisory authority or another authority under the same conditions. Which body that is per Member State does not follow from the Regulation.
- Applies when: Applies to every AI system that qualifies as high-risk under Article 6, along both routes: the system that falls under the Union harmonisation legislation of Annex I as a safety component of a product or as a product in its own right, and the system that falls within one of the areas of Annex III. For the Annex I route there is a limit that this Article does not state itself: Article 2(2), as replaced by Article 1, point (2)(a), of Regulation (EU) 2026/1744, makes only Article 6(1), Article 60a and Articles 102 to 112 applicable to systems related to products covered by Section B of Annex I. Article 8 is not in that list, so for Section B products, machinery among them since 27 July 2026, this provision does not bear. In addition, Article 2(13), inserted by Article 1, point (3), can limit the application of the requirements in Articles 9 to 15 and 17 to 25 for Section A products, but only once the delegated act it prescribes exists. Article 8 sets no additional threshold of its own: what is high-risk is the subject of Article 6 and not of this provision.
- Applies when: Compliance is not assessed in the abstract but against two measures at once: the intended purpose of the system, and the generally acknowledged state of the art on AI and AI-related technologies. The second measure lies outside the Regulation and has no fixed content, so what suffices changes without the text changing.
- Applies when: Paragraph 2 only comes into play where a product contains an AI system to which both the requirements of this Regulation and those of the Union harmonisation legislation listed in Section A of Annex I apply. For a system that is high-risk through Annex III alone, paragraph 2 has no bearing.
- Unless: The integration in paragraph 2 is a choice and not a duty: providers shall have a choice of integrating, as appropriate, the necessary testing and reporting processes, information and documentation they provide with regard to their product into documentation and procedures that already exist. Anyone who does not integrate breaches nothing. What the provision does not permit is doing less: the responsibility for full compliance with all applicable requirements under the sectoral harmonisation legislation stands undiminished.
- Applies when: The system is high-risk under Article 6 and the provider places it on the market or puts it into service.
- Unless: Risks arising only from misuse beyond any reasonably foreseeable use fall outside the mandatory scope.
- Applies when: The provider places a high-risk system on the market; public deployers also register their use.
- Unless: For most Annex III systems internal control suffices (Annex VI); a notified body is required for certain biometrics and where harmonised standards are lacking.
- Applies when: A high-risk system is supplied, modified, rebranded or placed on the Union market from outside the EU.
- Unless: Those acting solely as distributor or importer without the Article 25 triggers remain in that lighter role, with their own verification duties.
These are the questions you answer yourself. Praxikon shows which condition sits in which provision; whether your system meets it is yours to establish.
recruitment and selection
Candidate recommendation that automatically becomes a decision
An employer uses a system that ranks applicants and recommends a candidate to hire. In one setup a recruiter weighs that recommendation in their own assessment; in the other the outcome is applied automatically and a candidate is rejected without anyone looking at it.
Provenance: The Commission draft guidelines of 19 May 2026 address this case when determining whether an application falls under Annex III. The document is a consultation version: non-binding and not yet final.
Assess a recruitment system on its intended purpose rather than on whether a recruiter reviews the output, because adding or removing human involvement does not change its high-risk classification.
Draft guidelines on high-risk AI classification, 19 May 2026, annex on Annex III
AI articles on EU policy without substantive review
A website automatically publishes AI-generated articles about European policy. There is an editorial charter on paper, but nobody reviews the substance. Before publication only a spell check runs, and a second AI model reviews the text.
Provenance: The final Commission guidelines on Article 50 treat this case as a worked example under the transparency obligations. The document is non-binding.
An editorial charter on paper, a spell check and a second AI model do not count as human review, so without substantive fact checking by a person you must label the publication.
Commission Guidelines C(2026) 5054 final, 20.7.2026, worked examples under Article 50
AI summary of a council decision under editorial control
A news site places an AI-generated summary beneath a journalist's article about a recent town council decision. The editor in chief reads the summary on substance, checks the facts and signs off for publication.
Provenance: The final Commission guidelines on Article 50 treat this case as a worked example under the transparency obligations. The document is non-binding.
Do not rely on the editorial exception without substantive review by a competent person and a publicly identifiable holder of editorial responsibility, and note that any AI intervention after sign-off voids it.
Commission Guidelines C(2026) 5054 final, 20.7.2026, worked examples under Article 50
AI toy rewards children for dangerous challenges
A manufacturer markets an AI-powered toy that keeps children engaged by encouraging increasingly risky challenges, such as climbing furniture, exploring high shelves or handling sharp objects, in exchange for digital rewards and virtual praise.
Provenance: The Commission guidelines on prohibited AI practices treat this case as a worked example under Article 5. The document is non-binding: authoritative interpretation rests with the Court of Justice.
If children are among your users, assess every engagement and reward mechanism separately, because what counts as acceptable stimulation for adults can already be exploitation of children's curiosity and desire for rewards.
Commission Guidelines C(2025) 5052 final, 29.7.2025, worked examples under Article 5
No mandatory course format, no certificate, no exam and no AI officer
The Commission Q&A on AI literacy states that there is no one size fits all when it comes to AI literacy and that no strict requirements or mandatory trainings are imposed. On certification, the Q&A states literally that there is no need for a certificate and that organisations can keep an internal record of trainings or other guiding initiatives. On assessment, it states that Article 4 of the AI Act does not entail an obligation to measure the AI knowledge of employees. On governance, it states that no specific governance structure is mandated to comply with Article 4, so that unlike the data protection officer under the GDPR, no AI officer needs to be appointed. On the level, the Q&A states that following the Digital Omnibus amendment AI literacy remains an obligation for providers and deployers of AI systems, but that no specific or sufficient level is mandated and that the Regulation does not require guaranteeing any specific level of AI literacy of any individual. Against that, the Q&A states that simply relying on the AI systems' instructions for use or asking staff to read them might be ineffective, and that organisations should take into account general AI understanding within the organisation, whether they are a provider or a deployer, the risks associated with the systems deployed, staff knowledge gaps considering technical knowledge, experience, education and training, and contextual factors such as sector, purpose and affected populations. The Q&A further states that organisations may implement different levels of training or learning approaches depending on knowledge, experience, education and role, and that staff with a degree or experience in AI development are normally considered AI literate, while the organisation must still verify that those persons understand the specific AI systems of the organisation, know how to deal with them and are aware of all risks.
Commission Q&A on AI literacy, sections on required level, training formats, certificates, assessment of knowledge and governance structures (consulted 9 August 2026)
Article 4 reaches beyond your own staff, and the national supervisor enforces it
The Commission Q&A on AI literacy states that Article 4 applies to providers and deployers of AI systems and in addition to other persons dealing with the operation and use of AI systems on their behalf, covering persons broadly within the organisational remit, with a contractor, a service provider and a client given as examples. On clients, the Q&A states that they may need AI literacy depending on the specific risk, reasoning that affected persons should understand how decisions taken with the assistance of AI will have an impact on them. On geographic scope, the Q&A states that the AI Act's legal framework applies to both public and private actors inside and outside the EU as long as the AI system is placed on the Union market, used in the Union, or its use has an impact on people located in the EU. On supervision, the Q&A states that the supervision and enforcement of Article 4 is not with the AI Office but under the remit of national market surveillance authorities, and that supervision and enforcement began on 2 August 2026, while Article 4 itself entered into application on 2 February 2025. On sanctions, the Q&A states that national market surveillance authorities could impose penalties and other enforcement measures for infringements of Article 4, that this will be based on national laws that Member States were due to adopt by 2 August 2025, that any sanction must be proportionate and based on the individual case taking into account factors such as the nature and gravity of the infringement and its intentional or negligent character, and that sanctions are more likely if there is proof of an incident due to a lack of appropriate training and guidance. Article 4 is not listed in the enumeration in Article 99(4) of the AI Act, which covers only Articles 16, 22, 23, 24, 26, 31, 33(1), (3) and (4), 34 and 50, so the level of any penalty for Article 4 follows from national law rather than from the Regulation's own ceilings. The Q&A further states that Article 4 reinforces the transparency provisions of Article 13 and the human oversight provisions of Article 14 and indirectly contributes to the protection of affected persons, and that for deployers of high-risk systems the Article 26 obligation to ensure staff are trained to ensure human oversight is a distinct requirement; that requirement becomes applicable on 2 December 2027 for standalone Annex III systems and on 2 August 2028 for Annex I systems.
Commission Q&A on AI literacy, sections on target groups, geographic scope, supervision and enforcement, and sanctions (consulted 9 August 2026)
AI agents must disclose both their AI nature and on whose behalf they act
Point (31) of the guidelines of 20 July 2026 states that AI agents are covered by Article 50(1) if they are capable of interacting with the persons instructing them or with other natural persons in the execution of their tasks, citing as examples making bookings, managing correspondence, negotiating or concluding contracts and executing purchases. That same point requires AI agents to be designed and developed so that they disclose both their artificial nature and the person on whose behalf they are acting, given the need for transparency of the origin and of the delegation of authority and accountability for the consequences of their actions. This also applies in complex multi-agent architectures in which other agents interact directly with natural persons. Where the provider cannot reliably determine before placing on the market or putting into service whether the agent will directly interact with a natural person, the agent should be designed at the architecture level and instructed to disclose itself in every situation where it is reasonably likely to interact with a natural person, including where that person represents a legal entity. Agents should also disclose themselves to the persons instructing them at key steps such as authorisation, reporting and validation, including where the agent receives, processes or relies upon outputs generated by other AI systems rather than by a natural person, and at every new interaction. Point (63) adds that Article 50(2) may apply to AI agents where the agent takes an action whose output is AI-generated or manipulated content perceptible by natural persons, while intermediate processing steps such as reasoning and chain of thought and non-perceptible actions such as a web request or browser action fall outside that scope.
Commission Guidelines C(2026) 5054 final, Section 3.1.1 point (31) and Section 4.1.2 point (63)
Artistic or satirical work is not exempt but attenuated, and the informative character always prevails
Point (119) of the guidelines of 20 July 2026 describes an attenuated transparency obligation for deep fakes forming part of evidently artistic, creative, satirical, fictional or analogous works or programmes, where the obligation is limited to disclosure in an appropriate manner that does not hamper the display or enjoyment of the work. Point (120) describes the categories: artistic works are created for the purpose of art, including music, cinematographic works and visual arts; creative works involve creative choices, while works mainly motivated by functional or technical considerations cannot be regarded as creative; satirical works are intended to criticise society, politics, business or public figures through humoristic techniques; fictional works involve persons, objects, places, entities or events in an imaginary but verisimilitude setting; analogous works share core traits with those categories without fitting neatly into one. Point (122) states that it must be evident to the natural persons exposed to it that the content falls within one of those categories, that the categories must therefore be interpreted strictly given the lighter disclosure regime and the interests of freedom of expression and freedom of the arts and sciences, and that content whose nature is potentially unclear or ambiguous to the audience falls outside this lighter regime. Relevant factors, per that same point, are whether the content displays formats or styles characteristic of the category, the context in which it is presented, and audience expectations. That same point excludes content whose nature is exclusively informative or commercial and recognisable as such, citing news reporting, notes that advertisements or documentaries may be regarded as evidently creative or fictional in certain specific situations but not in others because the assessment is case-specific, and states that where the deep fake combines multiple characters, for example informative and creative, the informative character should always prevail and the standard labelling requirements apply. Point (123) stresses that these deep fakes are not excluded from the obligation: the deployer must still disclose the AI origin or manipulation, but may do so in an appropriate manner, and must in any case comply with Article 50(5). Point (124) states that reliance on the attenuated obligation cannot justify failing to respect the fundamental rights of individuals or the rights of rightsholders under Union intellectual property or data protection law. As examples within the categories the document cites movies featuring AI de-aged existing actors or digital replicas of deceased actors, AI-generated music in the style of existing artists, and an AI-manipulated image of an existing politician in a scene clearly meant as humorous criticism. Outside the categories the document places among others an AI-manipulated video in the style of a teleshopping channel, AI-generated images of celebrities implying involvement in activities that never happened, and an AI-manipulated video featuring a realistic synthetic influencer focused solely on displaying a sponsored product's functionalities.
Commission Guidelines C(2026) 5054 final, Section 6.1.3, points (119) to (124) and the accompanying example lists
EN 18286:2026: quality management system for EU AI Act regulatory purposes
EN 18286:2026 (Artificial intelligence: Quality management system for EU AI Act regulatory purposes) was drafted by CEN/CLC/JTC 21 under standardisation request M/613 and approved by CEN-CENELEC on 12 July 2026. It is the first JTC 21 deliverable to reach publication. According to a published coverage statement accompanying the standard, not yet confirmed by a second independent source, it addresses Article 17(1) points (a) to (m) and Article 11(1) first sentence, and expressly not Article 17(2) to (4) or Article 72. The standard is NOT currently cited in the Official Journal. The Article 40 presumption of conformity only attaches after that citation.
EN ISO/IEC 42001: artificial intelligence management system
ISO/IEC 42001:2023 is the first certifiable international standard for an AI management system, published on 18 December 2023 and structured on the plan-do-check-act cycle. The text was adopted unchanged as EN ISO/IEC 42001:2026, approved by CEN on 13 March 2026, with national implementation by the member standards bodies. This adoption is not a deliverable under standardisation request M/613: the standard is not cited in the Official Journal and therefore confers no presumption of conformity under Article 40. For Article 17, the designated deliverable under M/613 is EN 18286:2026; that standard is likewise not cited in the Official Journal.
ISO/IEC 12792: transparency taxonomy of AI systems
ISO/IEC 12792:2025 (Information technology: Artificial intelligence: Transparency taxonomy of AI systems) was published in November 2025 by ISO/IEC JTC 1/SC 42. It specifies a taxonomy of information elements to help stakeholders identify and address transparency needs, and describes the semantics of those elements and their relevance to different stakeholders' objectives. The text was adopted as a European standard as EN ISO/IEC 12792:2025. It is not cited in the Official Journal and therefore confers no presumption of conformity under Article 40. For Article 13 the designated deliverable is prEN 18229-3.
ISO/IEC 23894: guidance on risk management for AI
ISO/IEC 23894:2023 (Information technology: Artificial intelligence: Guidance on risk management) was published in February 2023 and is the first international standard dealing specifically with risk management for AI. It is non-prescriptive and built on the ISO 31000 structure. The text was adopted by CEN-CENELEC as EN ISO/IEC 23894:2024. It is not cited in the Official Journal and therefore confers no presumption of conformity under Article 40 of the AI Act. The deliverable intended to do so for Article 9 is prEN 18228.
- Annex III, point 1: biometrics
- Annex III, point 1, as that point stands in the Regulation, with its lettered subpoints and the exceptions named in them.
- Annex III, point 2: critical infrastructure
- Annex III, point 2, as that point stands in the Regulation, with its lettered subpoints and the exceptions named in them.
- Annex III, point 3: education and vocational training
- Annex III, point 3, as that point stands in the Regulation, with its lettered subpoints and the exceptions named in them.
- Annex III, point 4: employment and workers management
- Annex III, point 4, as that point stands in the Regulation, with its lettered subpoints and the exceptions named in them.
General interpretation, not legal advice. Checked against Regulation (EU) 2024/1689 and the Digital Omnibus (EU) 2026/1744; the official source remains authoritative.
Full map for your situation