Regulatory primer

EU AI Act

Regulation (EU) 2024/1689 — Artificial Intelligence Act · European Union · In force (phased applicability)

The EU AI Act is the first horizontal regulation of artificial intelligence systems anywhere. It bans certain AI practices outright, imposes detailed obligations on 'high-risk' AI, requires transparency for AI that interacts with humans, and governs general-purpose AI models. It came into force on 1 August 2024 and applies in phases through 2027.

Updated 15 May 2026·Reading time ~ 7 min·Regulator-first explainer

What it is

The AI Act is a horizontal regulation — it doesn't care what sector you're in, it cares about what kind of AI risk you're presenting. It uses four risk tiers: prohibited practices (Art. 5), high-risk systems (Art. 6 + Annex III), limited-risk transparency obligations (Art. 50), and minimal-risk systems (no obligations). General-purpose AI models have their own regime in Chapter V.

The Act was proposed by the European Commission in April 2021, agreed in trilogue December 2023, and adopted June 2024. The published text (Regulation (EU) 2024/1689) entered into force on 1 August 2024. Different chapters apply at different dates — prohibited practices applied 2 February 2025; GPAI obligations applied 2 August 2025; most high-risk obligations apply from 2 August 2026; the Art. 6(1) pathway (for AI in products under Annex I harmonisation legislation, including MDR) applies from 2 August 2027.

The enforcement architecture has two layers. The EU AI Office (inside the European Commission) supervises GPAI provider obligations and coordinates cross-border enforcement. National competent authorities (often the data protection authority, or a sector-specific regulator) supervise high-risk systems deployed inside their jurisdiction. Penalties go up to €35M or 7% of global turnover for breaches of prohibited practices; up to €15M or 3% for high-risk system breaches.

Who's in scope

  • Providers of AI systems placed on the EU market — including non-EU providers whose output is used in the EU.
  • Deployers (operators) of AI systems located in the EU, or whose AI output affects people in the EU.
  • Distributors + importers of AI systems destined for the EU market.
  • Providers of general-purpose AI models — including foundation-model providers, regardless of where they're established, if the model is made available in the EU.
  • The Act does NOT apply to AI used exclusively for military / defence / national security, scientific research + development before market placement, or purely personal non-professional use.

Key obligations

Art. 5 — prohibited practices

Banned outright: social scoring by public authorities, manipulative subliminal techniques exploiting vulnerabilities, untargeted scraping of facial images for biometric databases, emotion recognition in workplace + education (with medical / safety exceptions), real-time remote biometric identification in public spaces by law enforcement (with narrow exceptions).

Art. 6 + Annex III — high-risk classification

Art. 6(1): AI is high-risk if it's a safety component of (or itself is) a product under Annex I harmonisation legislation requiring third-party conformity assessment (e.g. MDR). Art. 6(2) + Annex III: AI in eight enumerated areas is high-risk — biometrics, critical infrastructure, education, employment, access to essential services + benefits, law enforcement, migration, administration of justice.

Art. 9 — risk management system

Providers of high-risk AI must establish + document a continuous risk-management process across the lifecycle: identify foreseeable risks, evaluate residual risks, adopt risk-management measures, test the system pre + post deployment.

Applies to: Providers of high-risk AI

Art. 10 — data governance

Training, validation, testing data sets must meet quality criteria: relevance, representativeness, freedom from errors, statistical properties appropriate for the intended purpose. Bias monitoring + mitigation obligations.

Applies to: Providers of high-risk AI

Art. 12 — automatic event logging

High-risk AI systems must technically allow for automatic recording of events ('logs') over the lifetime of the system. Logs must enable identification of situations that may pose risk, support post-market monitoring, and facilitate compliance verification.

Applies to: Providers + deployers of high-risk AI

Art. 13 — transparency to deployers

High-risk AI systems must be accompanied by instructions for use giving deployers the information needed to operate them properly — system limitations, expected output interpretation, human-oversight requirements.

Applies to: Providers of high-risk AI

Art. 14 — human oversight

High-risk AI systems must be designed to enable effective oversight by natural persons during their period of use. Deployers must be able to monitor outputs, intervene, override, and stop the system.

Applies to: Providers + deployers of high-risk AI

Art. 15 — accuracy, robustness, cybersecurity

High-risk AI must achieve appropriate accuracy, robustness, and cybersecurity levels. Performance metrics declared in instructions for use. Resilience against adversarial inputs + cybersecurity attacks designed in.

Applies to: Providers of high-risk AI

Art. 50 — transparency to users

Natural persons interacting with an AI system must be informed they're interacting with AI (unless obvious). AI-generated synthetic content (text, image, audio, video) must be machine-readably marked as AI-generated. Deepfakes have additional disclosure obligations.

Applies to: All providers + deployers

Art. 53 — GPAI provider obligations

General-purpose AI model providers must maintain technical documentation, training-data summary, copyright policy. GPAI models with systemic risk (>10^25 FLOPS or designated) have additional model-evaluation + incident-reporting + cybersecurity obligations.

Applies to: GPAI providers

Timeline + applicability

  • 1 Aug 2024Regulation entered into force.
  • 2 Feb 2025Art. 5 prohibited practices applicable. AI literacy obligations applicable.
  • 2 Aug 2025Chapter V GPAI obligations applicable (Art. 53 et seq.). National competent authorities designated.
  • 2 Aug 2026Most Chapter II/III obligations applicable — high-risk systems under Annex III.
  • 2 Aug 2027Art. 6(1) pathway applicable — high-risk AI as safety components of Annex I-listed products (e.g. medical devices under MDR).

What's still being worked out

Areas where the regulation's interpretation is genuinely unsettled. Vendor pages skip this; we don't. Your counsel is the right venue for definitive guidance on your deployment.

  • Where Art. 6(1) / Annex I-pathway high-risk classification stops and Art. 6(2) / Annex III-pathway begins for products that arguably hit both. The European Commission has signalled guidance but enforcement-practice clarity is pending.
  • How 'meaningful human oversight' (Art. 14) reads alongside GDPR Art. 22's 'meaningful human intervention'. The Schufa CJEU ruling and EDPB Guidelines WP251 inform the GDPR side; AI Act practice is still developing.
  • GPAI 'systemic risk' designation criteria beyond the 10^25 FLOPS threshold (Art. 51) — discretionary designation power held by the Commission, with first designations expected through 2026.
  • The relationship between AI Act conformity assessment and existing product-safety conformity assessment under Annex I legislation (especially MDR). Industry guidance from notified bodies + the AI Office is emerging.
  • Cross-border enforcement coordination between the AI Office, national competent authorities, and sector-specific regulators (DPAs, EIOPA, EBA). Concurrent jurisdiction is normal; resolution mechanisms are not yet battle-tested.

Sectors most affected

Primary sources

Where Promethean fits

Promethean ships the per-decision evidence layer that operationalises Art. 12 record-keeping for high-risk AI: hash-chained, Ed25519-signed L12 receipts capturing the spec, model identity, inputs (as SHA-256 hashes), outputs, reviewer verdicts, and fallback flags. The chain feeds Art. 14 human-oversight evidence (was a human meaningfully involved on this decision?), Art. 15 accuracy/robustness metrics (fallback rate, schema-validity rate), and contributes to Annex IV technical documentation via the Enterprise-tier handoff packets. For Art. 50 obligations, the spec's promptTemplate enforces the disclosure language and the spec hash binds it to every L12 entry.

What Promethean does NOT solve

  • Risk-management process design (Art. 9) — that's an organisational + product-management responsibility.
  • Training-data governance (Art. 10) — data-pipeline + ML-engineering responsibility.
  • AI Act conformity assessment + CE marking — that's notified-body work for the operator.
  • GPAI obligations (Art. 53 et seq.) — Promethean is downstream; the foundation-model provider holds the Chapter V duties.
  • Operator's broader compliance programme (DPIA, FRIA, market-monitoring plan, post-market surveillance plan).

FAQ

Is the EU AI Act in force?

Yes — it entered into force on 1 August 2024. Different chapters apply at different dates. Art. 5 prohibited practices applied 2 February 2025; GPAI obligations applied 2 August 2025; high-risk obligations under Annex III apply from 2 August 2026; the Art. 6(1) pathway (for AI in Annex I-listed products like medical devices) applies from 2 August 2027.

How is 'high-risk' defined?

Two pathways. Art. 6(1) applies to AI that is (or is a safety component of) a product covered by EU harmonisation legislation listed in Annex I — MDR, automotive safety, machinery, toys, etc. — and that's required to undergo third-party conformity assessment. Art. 6(2) + Annex III applies to AI in eight enumerated areas: biometrics, critical infrastructure, education, employment, essential services + benefits, law enforcement, migration, administration of justice. An AI system can be high-risk under both pathways simultaneously.

Does the EU AI Act apply to non-EU providers?

Yes — the Act has extraterritorial reach. Art. 2 covers providers placing AI systems on the EU market regardless of their establishment, deployers in the EU, and providers + deployers outside the EU when the AI's output is used in the EU. A US-based AI vendor whose model is used by an EU bank is in scope. A US employer screening EU candidates with AI is in scope.

What's the difference between Art. 14 (AI Act human oversight) and GDPR Art. 22 (automated decisions)?

Different but overlapping. AI Act Art. 14 is a design-time obligation on providers (the AI system must be designed to enable effective human oversight) plus a deployment-time obligation on deployers (use the oversight as intended). GDPR Art. 22 is a subject-rights obligation: individuals have the right not to be subject to solely-automated decisions with legal effects, unless an exception applies + safeguards (including meaningful human intervention) exist. They reinforce each other but cover different angles.

Do I need an AI Act audit?

It depends on your risk tier. High-risk AI providers need a conformity assessment before market placement — either internal (Art. 43(1)) or notified-body-conducted (Art. 43(3)). Deployers of high-risk AI need a Fundamental Rights Impact Assessment (Art. 27) before first use. GPAI providers maintain technical documentation. Limited-risk systems (Art. 50 transparency) typically don't require audit but require operational disclosure. Minimal-risk systems have no audit obligations.