← All laws

Compliance · Artificial intelligence

AI Act, the EU régulation on artificial intelligence.

The AI Act (EU régulation 2024/1689) is the first comprehensive AI regulatory framework worldwide. Adopted in June 2024, it is progressively applicable between August 2025 and August 2027. Here is what really applies to your organisation.

Luxgap explorer
Browse the 113 articles, the 180 recitals and the 13 annexes of the law, with Luxgap practical guidance
Browse articles → Browse recitals → Browse annexes →

Law contents

All 113 articles, in the order of the official text. Each one is analysed separately, with the official text and Luxgap practical guidance.

CHAPTER I — GENERAL PROVISIONS
CHAPTER II — PROHIBITED AI PRACTICES
CHAPTER III — HIGH-RISK AI SYSTEMS
CHAPTER IV — TRANSPARENCY OBLIGATIONS FOR PROVIDERS AND DEPLOYERS OF CERTAIN AI SYSTEMS
CHAPTER V — GENERAL-PURPOSE AI MODELS
CHAPTER VI — MEASURES IN SUPPORT OF INNOVATION
CHAPTER VII — GOVERNANCE
CHAPTER VIII — EU DATABASE FOR HIGH-RISK AI SYSTEMS
CHAPTER IX — POST-MARKET MONITORING, INFORMATION SHARING AND MARKET SURVEILLANCE
CHAPTER X — CODES OF CONDUCT AND GUIDELINES
CHAPTER XI — DELEGATION OF POWER AND COMMITTEE PROCEDURE
CHAPTER XII — PENALTIES
CHAPTER XIII — FINAL PROVISIONS

Annexes

Who is concerned?

Any organisation that develops, provides, imports, distributes or uses an AI system on the European market, whether as provider or deployer. If your teams use ChatGPT, Claude, Copilot, or an AI tool for HR screening, content moderation, décision automation, the AI Act applies.

Key obligations

Obligations depend on the risk level:

  • Unacceptable risk (banned): social scoring by authorities, cognitive manipulation, vulnerability exploitation, real-time biometric identification in public spaces (with strict exceptions).
  • High risk: HR (CV screening), access to éducation and essential services, law enforcement, border control, biometric identification. Major obligations: quality management system, technical documentation, human oversight, robustness, transparency, logging, CE marking.
  • Limited risk: chatbots, deepfakes, content generators. Main obligation: transparency.
  • Minimal risk: most uses. No specific obligation.

For general-purpose AI models (GPAI) like GPT-4, Claude, Gemini: technical documentation, training data transparency, copyright compliance.

Deadlines

  • 2 February 2025: banned practices.
  • 2 August 2025: GPAI model obligations, sanctions, governance.
  • 2 August 2026: full application to high-risk systems (except sector-specific products).
  • 2 August 2027: high-risk systems embedded in regulated products.

Sanctions for non-compliance

Heavy administrative sanctions: up to €35 million or 7% of worldwide turnover for banned practices; €15M or 3% for other AI obligation failures; €7.5M or 1% for incorrect information.

How Luxgap helps

The AI Act is part of our DPO mandate scope. Our AI advisory goes further: we deploy compliant-by-design AI agents (on-premise disconnected from the Internet for highly regulated sectors, or contractually scoped public GPAIs).

Let's discuss your situation.

This topic is handled case by case. Get in touch to discuss it: reply within one business day, no commitment.

Contact us →