EU AI Act requirements, risk classes and penalties
Regulation (EU) 2024/1689 assigns duties across four operator roles and four risk classes. This guide covers scope, prohibited practices, duties by role and supervision, with an article reference on every reviewed row.
Short answer
What does the EU AI Act require, and who must comply?
NovaCopilot holds Regulation (EU) 2024/1689 as a reviewed matrix. Providers, deployers, importers and distributors each have defined duties, alongside prohibited practices, risk classes, supervision and penalties. Every reviewed row carries its article and reading date, and the same rows are available by machine for each role.
Regulation (EU) 2024/1689
A source reference, not legal advice.
Scope
The Regulation applies to parties that place an AI system on the market, put it into service, import it or distribute it in the Union. The assessment therefore starts with the operator role. The same system can carry different duties for different parties.
- Legal act
- Regulation (EU) 2024/1689
- Common names
- EU AI Act, AI Act
- Operators
- Provider, deployer, importer, distributor
- Risk classes
- Prohibited, high risk, transparency risk, minimal risk
- General-purpose models
- Separate duties, with systemic risk as an additional level
- Supervision
- National market surveillance authorities and the AI Office
Matrix coverage
- Legal act
- Regulation (EU) 2024/1689
- Rows in the matrix
- 27
- Rows read
- 22
- Rows without a read requirement
- 5
- R, Risk and prohibitions
- 4 of 5 read
- P, Provider duties
- 8 of 9 read
- D, Deployment and distribution
- 5 of 5 read
- M, General-purpose models
- 2 of 3 read
- GRC, Supervision, enforcement and penalties
- 3 of 5 read
Requirements row by row
- R1prohibited practicesprohibited practicesArticle 5
Chapter II identifies the prohibited practices.
- R2high riskhigh-risk systems under Annex IIIArticle 6
Article 6 determines when a system is classified as high risk.
- R3transparency risktransparency duties under Chapter IVArticle 50
Chapter IV sets the transparency duties for certain AI systems.
- R4systemic riskgeneral-purpose model with systemic riskArticle 55
Article 55 sets the additional duties for systemic-risk models in Chapter V.
- P1risk managementrisk management systemArticle 9
The provider establishes and maintains a risk management system.
- P2data governancedata and data governanceArticle 10
Data and data governance requirements apply to training, validation and testing.
- P3documentationtechnical documentationArticle 11
Technical documentation is prepared and kept up to date.
- P4record keepingautomatic record keepingArticle 12
The system enables automatic recording of events.
- P5accuracy, robustness and cybersecurityaccuracy, robustness and cybersecurityArticle 15
Requirements apply to accuracy, robustness and cybersecurity.
- P6provider obligationsprovider obligationsArticle 16
The provider duties for high-risk systems.
- P7quality managementquality management systemArticle 17
The provider operates a quality management system.
- P8conformity assessmentconformity assessmentArticle 43
A conformity assessment is completed before the system is placed on the market.
- D1deploymentuse according to instructions and human oversightArticle 26
The deployer follows the instructions and assigns human oversight.
- D2fundamental rights impact assessmentfundamental rights impact assessmentArticle 27
A fundamental rights impact assessment is completed where required.
- D3importer dutiesimporter verificationArticle 23
The importer verifies conformity, documentation and marking.
- D4distributor dutiesdistributor verificationArticle 24
The distributor verifies marking and documentation.
- D5transparencydisclosure of AI interaction and content labellingArticle 50
Users are informed when they interact with an AI system, and certain content is labelled.
- M1model documentationmodel documentation and copyright policyArticle 53
The model is documented and covered by a copyright policy.
- M2systemic riskadditional duties for systemic riskArticle 55
Additional duties apply to models with systemic risk.
- GRC1post-market monitoringpost-market monitoringArticle 72
The system is monitored after being placed on the market.
- GRC2serious incidentsreporting of serious incidentsArticle 73
Serious incidents are reported to the market surveillance authority.
- GRC3penaltiespenalty framework under Article 99Article 99
Chapter XII sets the penalty framework.
Rows without a read requirement
These rows retain a stable address but make no claim. They are completed only when the requirement has been read from the official text.
- R5minimal risknot yet read
Minimal risk has no separate legal basis in the Regulation.
- P9harmonised standardsnot yet read
The harmonised standards have not yet been entered in the register.
- M3systemic risk thresholdnot yet read
The systemic-risk threshold is set through delegated acts not yet entered in the register.
- GRC4registrationnot yet read
The Chapter VIII registration duties have not yet been entered article by article.
- GRC5national supervisionnot yet read
The national supervisory authorities have not yet been entered in the register.
Roles covered by the matrix
- Party placing the system on the market
- provider
- Party using the system in its operations
- deployer
- Party bringing a system in from a third country
- importer
- Party making the system available further
- distributor
- Party providing a general-purpose AI model
- model provider
Working order for legal teams
- Map every AI system the client places on the market, deploys or imports, and record the operator role for each one.
- Test each system against the Chapter II prohibitions before classifying risk.
- Determine the risk class and record the legal basis with an article reference.
- Allocate duties to the correct operator in contracts, so responsibility follows the party able to meet it.
- Review the article-level change feed on a fixed schedule.
Machine surfaces for the same content
- Agent manifest/api/public/v1/ai-act/agent/manifest.json
- Run by role/api/public/v1/ai-act/agent/run
- Verification view/api/public/v1/ai-act/agent/verify
- Machine description/api/public/v1/ai-act/agent/ai.json
- Derived data points/api/public/v1/open/derived?act=ai-act
- Article-level change feed/api/public/v1/diff/eu/ai-act
Related pages
Reservation
This material supports compliance work and is not legal advice. The official wording prevails over every derived row.
Ready-made pack
AI Act compliance pack
€199, one-time purchase
The AI Act as working material: the articles, the high-risk requirements, the documentation duties and a structure for the risk assessment.
Next step
Three ways to put the register to work in your own practice.
Start with your task
Litigation
Find support in a judgment
Search guiding decisions, see what became final and follow changes in the law.
In-house, deals
Map the rules in a transaction
Move from theme to act and on to the article that carries the duty.
Compliance
Assess the risk in a process
Risk scoring per legal area, with the sources behind every score.