Regulation (EU) 2024/1689
The EU AI Act Rules for everyone who provides or uses AI.
The AI Act classifies AI by risk. Some practices are banned, high-risk AI faces strict obligations, and other systems must meet transparency rules. Obligations apply in stages, and some already apply.
At a glance
- Legal basis
- Regulation (EU) 2024/1689, amended by Regulation (EU) 2026/1744
- In force since
- 1 August 2024; obligations phased in until 2028
- Roles
- Provider, deployer, importer, distributor – if you only use AI in your own operations, you are a deployer
- Fines
- Up to €35m or 7% of worldwide turnover for prohibited practices; up to €15m or 3% for other obligations (Art. 99)
Who the AI Act applies to
- Providers that develop AI systems or place them on the market under their own name.
- Deployers that use AI systems in their own operations, from chat assistants to candidate screening.
- Companies outside the EU too, if their AI is used in the EU.

What the AI Act requires
- 01
Prohibited practices (Art. 5)
Such as social scoring or manipulative techniques. Has applied since 2 February 2025. From 2 December 2026, AI that generates non-consensual intimate images or child sexual abuse material is also prohibited.
- 02
AI literacy (Art. 4)
Providers and deployers take measures to support AI literacy among their staff. Has applied since 2 February 2025.
- 03
Transparency (Art. 50)
People must be able to tell that they are dealing with AI or seeing AI-generated content. Has applied since 2 August 2026. Systems placed on the market before that date must mark AI content from 2 December 2026.
- 04
High-risk AI
Risk management, data quality, logging, human oversight and conformity assessment. For Annex III from 2 December 2027.
Deadlines and dates
Prohibitions and AI literacy apply
Obligations for general-purpose AI models
Transparency obligations under Art. 50
New prohibition under Art. 5; marking under Art. 50(2) also for older systems
High-risk AI under Annex III (postponed by Regulation (EU) 2026/1744)
High-risk AI in products under Annex I (postponed by Regulation (EU) 2026/1744)
How UniqSuite helps
UniqSuite starts with an AI register: which systems exist, who uses them, what your role is and which risk class they fall into. This shows which AI Act obligations you check for each system.
Frequently asked questions
We only use a chat assistant. Does this affect us?
Yes, as a deployer. You must already take measures to support the AI literacy of your staff, and depending on the use, transparency obligations apply as well.
Does the AI Act apply on top of NIS2?
Yes. Both apply independently. Many measures, such as access control and logging, help with both.
When is an AI system high-risk?
When it is used in one of the areas listed in Annex III, such as selecting job candidates or assessing creditworthiness. AI that is a safety component of a product under Annex I, or is itself such a product, is high-risk too if the product requires third-party assessment. By way of exception, an Annex III system is not high-risk if it poses no significant risk to health, safety or fundamental rights. If it profiles individuals, it is always high-risk (Art. 6).
How do we demonstrate AI literacy?
The Regulation does not require a certificate. Document your measures, for example the type and scope of training and who took part.
What applies to public authorities?
Bodies governed by public law and private entities providing public services must carry out a fundamental rights impact assessment before deploying a high-risk AI system under Annex III (Art. 27). Systems for critical infrastructure are excluded. The obligation applies from 2 December 2027.
See what is still open for you.
In half an hour we show you how UniqSuite organises the requirements, makes gaps visible and produces evidence.
