Guides

The EU AI Act, explained clearly.

A concise, sourced reference to Regulation (EU) 2024/1689 — what it requires, of whom, and by when. Written for compliance, legal and product teams; free of jargon and free of scare tactics.

01

Understanding the EU AI Act

What the Regulation is, the risk-based approach it takes, who it applies to, and why your role in the value chain matters more than you might expect.

Read guide →
02

Provider or deployer? Why your role decides your duties

The same AI system carries very different obligations depending on your role in the value chain — and you can become a provider without meaning to.

Read guide →
03

High-risk AI systems: classification and obligations

How a system becomes high-risk under Articles 6 and 7, the eight Annex III areas, the Article 6(3) filter, and the core duties that follow for providers and deployers.

Read guide →
04

The seven requirements for high-risk systems (Articles 9–15)

Risk management, data governance, documentation, logging, transparency, human oversight, and accuracy — the seven essential requirements a high-risk system must satisfy, in plain terms.

Read guide →
05

Prohibited AI practices (Article 5)

Eight AI practices are banned outright under the Act — in force since February 2025, and carrying the heaviest penalties. A plain-language list.

Read guide →
06

Technical documentation (Article 11 & Annex IV)

What the technical documentation of a high-risk system must contain, when it must exist, and the simplified route available to SMEs.

Read guide →
07

Conformity assessment, CE marking & registration

Before a high-risk system reaches the market, it must pass a conformity assessment, carry the CE marking, and be registered in the EU database. How each step works.

Read guide →
08

The fundamental-rights impact assessment (Article 27)

Some deployers of high-risk systems must assess the impact on fundamental rights before deployment. Who is caught, and what the assessment must contain.

Read guide →
09

Transparency obligations under Article 50

Article 50 is not a single duty but four — with different obligated parties and exceptions. A practical breakdown for providers and deployers.

Read guide →
10

Serious-incident reporting (Article 73)

When a high-risk system causes a serious incident, providers must report it to the authorities — within deadlines that vary by severity. The definition, the clocks, and who does what.

Read guide →
11

General-purpose AI (GPAI): who is caught, and how

The Act has a distinct regime for large foundation models. Who qualifies as a GPAI provider, the compute thresholds, and an honest note on who this really affects.

Read guide →
12

The AI Act application timeline

The Act entered into force in August 2024, but its obligations phase in over years. The dates that actually put duties on your systems — and why a static report goes stale.

Read guide →
13

Penalties and enforcement

Who enforces the AI Act, the three tiers of fines, and why the proportionate treatment of SMEs matters more than the headline numbers.

Read guide →

These guides are reference material for orientation, not legal advice. The authoritative source is the Official Journal text of Regulation (EU) 2024/1689 (12 July 2024).