01
Scope of application & addressees
- Providers and deployers placing or using AI systems in the European Union
- Providers placing general-purpose AI models on the EU market
- Certain non-EU operators where system output is used in the European Union
02
Core regulatory mandates & key requirements
01The Act prohibits defined AI practices that create unacceptable risks.
02High-risk systems require risk management, data governance, technical documentation, logging, human oversight and conformity assessment.
03General-purpose AI providers face documentation, downstream information, copyright-policy and systemic-risk obligations.
03
Enforcement & compliance timeline
The Act entered into force.
Prohibited practices and AI literacy provisions began to apply.
Certain general-purpose AI rules began to apply.
Revised timing rules for high-risk systems entered into force.
Most governance, transparency and enforcement provisions began to apply.
Rules for Annex III high-risk use cases begin to apply.
Rules for high-risk systems embedded in regulated products begin to apply.