Legal sources with official primary sources

Printed ·

Skip to main content
Skip to the answer

EU AI Act requirements, risk classes and penalties

Regulation (EU) 2024/1689 assigns duties across four operator roles and four risk classes. This guide covers scope, prohibited practices, duties by role and supervision, with an article reference on every reviewed row.

Share this page

Scope

The Regulation applies to parties that place an AI system on the market, put it into service, import it or distribute it in the Union. The assessment therefore starts with the operator role. The same system can carry different duties for different parties.

Legal act
Regulation (EU) 2024/1689
Common names
EU AI Act, AI Act
Operators
Provider, deployer, importer, distributor
Risk classes
Prohibited, high risk, transparency risk, minimal risk
General-purpose models
Separate duties, with systemic risk as an additional level
Supervision
National market surveillance authorities and the AI Office

Matrix coverage

Legal act
Regulation (EU) 2024/1689
Rows in the matrix
27
Rows read
22
Rows without a read requirement
5
R, Risk and prohibitions
4 of 5 read
P, Provider duties
8 of 9 read
D, Deployment and distribution
5 of 5 read
M, General-purpose models
2 of 3 read
GRC, Supervision, enforcement and penalties
3 of 5 read

Requirements row by row

  • R1prohibited practicesprohibited practicesArticle 5

    Chapter II identifies the prohibited practices.

  • R2high riskhigh-risk systems under Annex IIIArticle 6

    Article 6 determines when a system is classified as high risk.

  • R3transparency risktransparency duties under Chapter IVArticle 50

    Chapter IV sets the transparency duties for certain AI systems.

  • R4systemic riskgeneral-purpose model with systemic riskArticle 55

    Article 55 sets the additional duties for systemic-risk models in Chapter V.

  • P1risk managementrisk management systemArticle 9

    The provider establishes and maintains a risk management system.

  • P2data governancedata and data governanceArticle 10

    Data and data governance requirements apply to training, validation and testing.

  • P3documentationtechnical documentationArticle 11

    Technical documentation is prepared and kept up to date.

  • P4record keepingautomatic record keepingArticle 12

    The system enables automatic recording of events.

  • P5accuracy, robustness and cybersecurityaccuracy, robustness and cybersecurityArticle 15

    Requirements apply to accuracy, robustness and cybersecurity.

  • P6provider obligationsprovider obligationsArticle 16

    The provider duties for high-risk systems.

  • P7quality managementquality management systemArticle 17

    The provider operates a quality management system.

  • P8conformity assessmentconformity assessmentArticle 43

    A conformity assessment is completed before the system is placed on the market.

  • D1deploymentuse according to instructions and human oversightArticle 26

    The deployer follows the instructions and assigns human oversight.

  • D2fundamental rights impact assessmentfundamental rights impact assessmentArticle 27

    A fundamental rights impact assessment is completed where required.

  • D3importer dutiesimporter verificationArticle 23

    The importer verifies conformity, documentation and marking.

  • D4distributor dutiesdistributor verificationArticle 24

    The distributor verifies marking and documentation.

  • D5transparencydisclosure of AI interaction and content labellingArticle 50

    Users are informed when they interact with an AI system, and certain content is labelled.

  • M1model documentationmodel documentation and copyright policyArticle 53

    The model is documented and covered by a copyright policy.

  • M2systemic riskadditional duties for systemic riskArticle 55

    Additional duties apply to models with systemic risk.

  • GRC1post-market monitoringpost-market monitoringArticle 72

    The system is monitored after being placed on the market.

  • GRC2serious incidentsreporting of serious incidentsArticle 73

    Serious incidents are reported to the market surveillance authority.

  • GRC3penaltiespenalty framework under Article 99Article 99

    Chapter XII sets the penalty framework.

Rows without a read requirement

These rows retain a stable address but make no claim. They are completed only when the requirement has been read from the official text.

  • R5minimal risknot yet read

    Minimal risk has no separate legal basis in the Regulation.

  • P9harmonised standardsnot yet read

    The harmonised standards have not yet been entered in the register.

  • M3systemic risk thresholdnot yet read

    The systemic-risk threshold is set through delegated acts not yet entered in the register.

  • GRC4registrationnot yet read

    The Chapter VIII registration duties have not yet been entered article by article.

  • GRC5national supervisionnot yet read

    The national supervisory authorities have not yet been entered in the register.

Roles covered by the matrix

Party placing the system on the market
provider
Party using the system in its operations
deployer
Party bringing a system in from a third country
importer
Party making the system available further
distributor
Party providing a general-purpose AI model
model provider

Working order for legal teams

  • Map every AI system the client places on the market, deploys or imports, and record the operator role for each one.
  • Test each system against the Chapter II prohibitions before classifying risk.
  • Determine the risk class and record the legal basis with an article reference.
  • Allocate duties to the correct operator in contracts, so responsibility follows the party able to meet it.
  • Review the article-level change feed on a fixed schedule.

Machine surfaces for the same content

Related pages

Reservation

This material supports compliance work and is not legal advice. The official wording prevails over every derived row.

Ready-made pack

AI Act compliance pack

€199, one-time purchase

The AI Act as working material: the articles, the high-risk requirements, the documentation duties and a structure for the risk assessment.

Next step

Three ways to put the register to work in your own practice.

Start with your task