The EU AI Act in fifteen minutes
Shared methods · A shared method; linked tool guides explain the exact steps.
This page covers tools outside your selection. You can still read it. Find matching guides
A risk-based law, not a technology law. Four tiers, and most people using these tools sit in the lowest one with two obligations that still apply.
The AI Act regulates uses, and it does so by risk. The same model can sit in three different tiers depending on what you point it at, which is the single fact that makes the law legible once you have it and confusing until you do.
It entered into force on 1 August 2024 and applies in phases.
Four tiers, shortest version
Unacceptable — prohibited outright. Nine practices the Commission describes as "a clear threat to the safety, livelihoods and rights of people": social scoring, untargeted scraping of facial images, emotion recognition in the workplace, and others. Eight took effect on 2 February 2025; the ninth applies from December 2026. If you are doing one of these, no compliance process makes it lawful.
High risk. Systems posing "serious risks to health, safety or fundamental rights" — AI in critical infrastructure, education scoring, employment decisions, credit assessment, biometric identification, law enforcement, asylum processing. Heavy obligations: risk assessment, data quality, logging, documentation, human oversight, robustness. These apply from 2 December 2027.
Transparency risk. Disclosure duties. People should know when they are interacting with an AI system, and providers of generative AI must ensure AI-generated content is identifiable. Deep fakes and text published in the public interest need clear marking. Applied from August 2026.
Minimal or no risk. Everything else, which the Commission notes is the vast majority of systems. No specific requirements under the Act.
Where you probably actually are
Most organisations reading this use one of these tools for drafting, summarising, research and code. That is minimal-risk territory, and the honest answer is that the Act's heavy machinery does not apply to it.
Two things still do.
AI literacy. Article 4 has required it of staff since 2 February 2025, regardless of tier. It is the obligation most people have and fewest have addressed. See the literacy obligation, practically.
Transparency, where it bites. If you publish AI-generated text in the public interest, or produce synthetic media, the Article 50 duties are yours. Internal drafting does not trigger them.
The trap runs the other way from what people expect. The risk is not that ordinary use is secretly high-risk; it is deciding a use is minimal because the tool is general-purpose, when the application is a hiring filter or a credit decision. Tier follows the use.
Provider or deployer
The Act splits duties. Providers carry the upstream burden — documentation, risk mitigation, monitoring. Deployers ensure human oversight and report serious incidents.
Buying one of these tools and using it makes you a deployer, which is much the lighter side — though a public-sector deployer carries extra weight, since its outputs speak with state authority. Building something on the API and putting your name on it can make you a provider, and that is a different set of obligations rather than a bigger version of the same one. The distinction and the dates are worked through in the AI Act calendar.
The dates, in one place
| Date | What applies |
|---|---|
| 1 August 2024 | Entry into force |
| 2 February 2025 | Prohibitions and the AI literacy obligation |
| 2 August 2025 | Governance and general-purpose AI model rules |
| 2 August 2026 | General application; enforcement begins |
| 2 December 2027 | High-risk system rules |
| 2 August 2028 | Extended deadline for high-risk systems inside regulated products |
What goes wrong
Reading it as a technology law. Nothing is regulated for being AI. Uses are regulated for what they decide and about whom, so "are we compliant" has no answer until you name the use.
Assuming minimal risk because the tool is general-purpose. The tier follows the application. A general model inside a hiring process is in a hiring process.
Treating August 2026 as the deadline. General application began then, and the prohibitions and literacy duty preceded it by eighteen months. Something is already required of nearly everyone.
Waiting for someone to specify the literacy requirement. No format is mandated, deliberately, and that is not a reason to have done nothing. The standard is proportionate effort, which you can only fail by omission.
Confusing this with the GDPR. They overlap and are separate instruments with separate obligations. Satisfying one says nothing about the other.
How to check
Write down the concrete use, the decision it affects, and the people affected. Check the relevant category and date against the linked Commission material, then have the person responsible for that use review the classification. Keep the source and review date with the decision so a later product change does not silently inherit an outdated assessment.
Further reading
The literacy obligation for Article 4, which is the part that already applies to nearly everyone. The AI Act calendar for provider-versus-deployer and what is still ahead. And what data may go into a model, which is where the AI Act and data protection law meet in practice.
Sources
- AI Act — regulatory framework, European Commission Tier 1 2026-09-02
- AI Act implementation timeline Tier 3 2026-09-02
- Transparency obligations under Article 50 AI Act — European Commission FAQ Tier 1 2026-09-02
Something wrong with this page?
Say what you expected and what you got. That is usually the shortest route to a correction, and it goes on the public issue tracker so the fix is visible.