AI Act, the EU régulation on artificial intelligence.
The AI Act (EU régulation 2024/1689) is the first comprehensive AI regulatory framework worldwide. Adopted in June 2024, it is progressively applicable between August 2025 and August 2027. Here is what really applies to your organisation.
Law contents
All 113 articles, in the order of the official text. Each one is analysed separately, with the official text and Luxgap practical guidance.
- 6. Classification rules for high-risk AI systems
- 7. Amendments to Annex III
- 8. Compliance with the requirements
- 9. Risk management system
- 10. Data and data governance
- 11. Technical documentation
- 12. Record-keeping
- 13. Transparency and provision of information to deployers
- 14. Human oversight
- 15. Accuracy, robustness and cybersecurity
- 16. Obligations of providers of high-risk AI systems
- 17. Quality management system
- 18. Documentation keeping
- 19. Automatically generated logs
- 20. Corrective actions and duty of information
- 21. Cooperation with competent authorities
- 22. Authorised representatives of providers of high-risk AI systems
- 23. Obligations of importers
- 24. Obligations of distributors
- 25. Responsibilities along the AI value chain
- 26. Obligations of deployers of high-risk AI systems
- 27. Fundamental rights impact assessment for high-risk AI systems
- 28. Notifying authorities
- 29. Application of a conformity assessment body for notification
- 30. Notification procedure
- 31. Requirements relating to notified bodies
- 32. Presumption of conformity with requirements relating to notified bodies
- 33. Subsidiaries of notified bodies and subcontracting
- 34. Operational obligations of notified bodies
- 35. Identification numbers and lists of notified bodies
- 36. Changes to notifications
- 37. Challenge to the competence of notified bodies
- 38. Coordination of notified bodies
- 39. Conformity assessment bodies of third countries
- 40. Harmonised standards and standardisation deliverables
- 41. Common specifications
- 42. Presumption of conformity with certain requirements
- 43. Conformity assessment
- 44. Certificates
- 45. Information obligations of notified bodies
- 46. Derogation from conformity assessment procedure
- 47. EU declaration of conformity
- 48. CE marking
- 49. Registration
- 51. Classification of general-purpose AI models as general-purpose AI models with systemic risk
- 52. Procedure
- 53. Obligations for providers of general-purpose AI models
- 54. Authorised representatives of providers of general-purpose AI models
- 55. Obligations of providers of general-purpose AI models with systemic risk
- 56. Codes of practice
- 57. AI regulatory sandboxes
- 58. Detailed arrangements for, and functioning of, AI regulatory sandboxes
- 59. Further processing of personal data for developing certain AI systems in the public interest in the AI regulatory sandbo
- 60. Testing of high-risk AI systems in real world conditions outside AI regulatory sandboxes
- 61. Informed consent to participate in testing in real world conditions outside AI regulatory sandboxes
- 62. Measures for providers and deployers, in particular SMEs, including start-ups
- 63. Derogations for specific operators
- 64. AI Office
- 65. Establishment and structure of the European Artificial Intelligence Board
- 66. Tasks of the Board
- 67. Advisory forum
- 68. Scientific panel of independent experts
- 69. Access to the pool of experts by the Member States
- 70. Designation of national competent authorities and single points of contact
- 72. Post-market monitoring by providers and post-market monitoring plan for high-risk AI systems
- 73. Reporting of serious incidents
- 74. Market surveillance and control of AI systems in the Union market
- 75. Mutual assistance, market surveillance and control of general-purpose AI systems
- 76. Supervision of testing in real world conditions by market surveillance authorities
- 77. Powers of authorities protecting fundamental rights
- 78. Confidentiality
- 79. Procedure at national level for dealing with AI systems presenting a risk
- 80. Procedure for dealing with AI systems classified by the provider as non-high-risk in application of Annex III
- 81. Union safeguard procedure
- 82. Compliant AI systems which present a risk
- 83. Formal non-compliance
- 84. Union AI testing support structures
- 85. Right to lodge a complaint with a market surveillance authority
- 86. Right to explanation of individual decision-making
- 87. Reporting of infringements and protection of reporting persons
- 88. Enforcement of the obligations of providers of general-purpose AI models
- 89. Monitoring actions
- 90. Alerts of systemic risks by the scientific panel
- 91. Power to request documentation and information
- 92. Power to conduct evaluations
- 93. Power to request measures
- 94. Procedural rights of economic operators of the general-purpose AI model
- 95. Codes of conduct for voluntary application of specific requirements
- 96. Guidelines from the Commission on the implementation of this Regulation
- 99. Penalties
- 100. Administrative fines on Union institutions, bodies, offices and agencies
- 101. Fines for providers of general-purpose AI models
- 102. Amendment to Regulation (EC) No 300/2008
- 103. Amendment to Regulation (EU) No 167/2013
- 104. Amendment to Regulation (EU) No 168/2013
- 105. Amendment to Directive 2014/90/EU
- 106. Amendment to Directive (EU) 2016/797
- 107. Amendment to Regulation (EU) 2018/858
- 108. Amendments to Regulation (EU) 2018/1139
- 109. Amendment to Regulation (EU) 2019/2144
- 110. Amendment to Directive (EU) 2020/1828
- 111. AI systems already placed on the market or put into service and general-purpose AI models already placed on the marked
- 112. Evaluation and review
- 113. Entry into force and application
Annexes
- I. List of Union harmonisation legislation
- II. List of criminal offences referred to in Article 5(1), first subparagraph, point (h)(iii)
- III. High-risk AI systems referred to in Article 6(2)
- IV. Technical documentation referred to in Article 11(1)
- V. EU declaration of conformity
- VI. Conformity assessment procedure based on internal control
- VII. Conformity based on an assessment of the quality management system and an assessment of the technical documentation
- VIII. Information to be submitted upon the registration of high-risk AI systems in accordance with Article 49
- IX. Information to be submitted upon the registration of high-risk AI systems listed in Annex III in relation to testing in
- X. Union legislative acts on large-scale IT systems in the area of Freedom, Security and Justice
- XI. Technical documentation referred to in Article 53(1), point (a) — technical documentation for providers of general-purpo
- XII. Transparency information referred to in Article 53(1), point (b) — technical documentation for providers of general-purp
- XIII. Criteria for the designation of general-purpose AI models with systemic risk referred to in Article 51
Who is concerned?
Any organisation that develops, provides, imports, distributes or uses an AI system on the European market, whether as provider or deployer. If your teams use ChatGPT, Claude, Copilot, or an AI tool for HR screening, content moderation, décision automation, the AI Act applies.
Key obligations
Obligations depend on the risk level:
- Unacceptable risk (banned): social scoring by authorities, cognitive manipulation, vulnerability exploitation, real-time biometric identification in public spaces (with strict exceptions).
- High risk: HR (CV screening), access to éducation and essential services, law enforcement, border control, biometric identification. Major obligations: quality management system, technical documentation, human oversight, robustness, transparency, logging, CE marking.
- Limited risk: chatbots, deepfakes, content generators. Main obligation: transparency.
- Minimal risk: most uses. No specific obligation.
For general-purpose AI models (GPAI) like GPT-4, Claude, Gemini: technical documentation, training data transparency, copyright compliance.
Deadlines
- 2 February 2025: banned practices.
- 2 August 2025: GPAI model obligations, sanctions, governance.
- 2 August 2026: full application to high-risk systems (except sector-specific products).
- 2 August 2027: high-risk systems embedded in regulated products.
Sanctions for non-compliance
Heavy administrative sanctions: up to €35 million or 7% of worldwide turnover for banned practices; €15M or 3% for other AI obligation failures; €7.5M or 1% for incorrect information.
How Luxgap helps
The AI Act is part of our DPO mandate scope. Our AI advisory goes further: we deploy compliant-by-design AI agents (on-premise disconnected from the Internet for highly regulated sectors, or contractually scoped public GPAIs).
Let's discuss your situation.
This topic is handled case by case. Get in touch to discuss it: reply within one business day, no commitment.
Contact us →