EU AI Act

The EU AI Act is Regulation (EU) 2024/1689 laying down harmonised rules on artificial intelligence. It regulates AI systems according to their risk: individual practices are prohibited, high-risk systems carry extensive obligations, and further systems are subject to transparency requirements.

EU AI ActLast reviewed:

The EU AI Act is Regulation (EU) 2024/1689, formally the regulation on artificial intelligence and known in Germany as the KI-Verordnung. It is the first comprehensive legal framework for artificial intelligence and follows the logic of product law: obligations attach to the AI system and to the role an organisation takes in relation to it.

The roles

The regulation distinguishes above all between the provider, who develops an AI system and places it on the market under their own name, and the deployer, who uses a system under their own responsibility. Importers and distributors come in addition. For most companies the deployer role is the relevant one, with one important qualification: anyone who offers a bought-in system under their own name, or substantially changes its intended purpose, can become a provider themselves.

The risk-based approach

TierExamplesLegal consequence
Prohibited practicessocial scoring, exploiting vulnerability, emotion recognition in the workplace and in education, untargeted scraping of facial imagesprohibition under Article 5
High-risk AIsystems under Annex III, for instance in employment, creditworthiness assessment or critical infrastructure, plus safety components in products under Annex Icomprehensive provider and deployer obligations
Systems subject to transparencychatbots, systems generating synthetic contentdisclosure and marking under Article 50
All other systemsthe majority of business applicationsno specific obligations under the regulation

For general-purpose AI models the regulation contains a chapter of its own, with duties on technical documentation, information for downstream providers and copyright; models with systemic risk carry additional requirements.

Obligations for high-risk systems

Providers must, among other things, operate a risk management system across the whole lifecycle, meet requirements on data and data governance, keep technical documentation and automatic logs, provide transparency towards deployers, enable human oversight, and ensure accuracy, robustness and cybersecurity. On top of that come a quality management system, a conformity assessment, the CE marking and registration.

Deployers carry a separate and considerably slimmer set of duties: use in line with the intended purpose, ensuring appropriate human oversight, suitability of input data within their own sphere of influence, retention of logs, and informing affected staff before a high-risk system is used in the workplace.

Independently of the risk tier, Article 4(1), in the new wording that has applied since 27 July 2026, requires providers and deployers to take measures to support the development of AI literacy of the staff working with AI; no specific level has to be guaranteed.

The phased timeline

The regulation entered into force on 1 August 2024; the staging sits in Article 113. The Digital Omnibus Regulation (EU) 2026/1744 of 8 July 2026 amended that article. The position after that amendment:

DateWhat applies
2 February 2025Chapters I and II: the prohibited practices under Article 5 and the AI literacy duty under Article 4
2 August 2025obligations for general-purpose AI models, governance and penalties
2 August 2026general applicability, including the transparency duties under Article 50
2 December 2026the prohibited practices newly added by the Digital Omnibus; also the deadline for labelling legacy systems
2 December 2027high-risk requirements for standalone systems under Article 6(2) and Annex III
2 August 2028high-risk requirements for product-embedded systems under Article 6(1) and Annex I

Two points routinely get lost here. First, 2 August 2026 was not postponed: only Chapter III, Sections 1 to 3 - the high-risk requirements - moved. Second, legacy systems have a deadline of their own. Under the new Article 111(4), providers of AI systems that generate synthetic audio, image, video or text content and were placed on the market before 2 August 2026 have to meet the labelling duty in Article 50(2) by 2 December 2026.

For legacy high-risk systems the position runs the other way: under Article 111(2) they are only caught if their design is substantially modified after Chapter III becomes applicable. Systems intended for use by public authorities, by contrast, have to meet the requirements by 2 August 2030.

Supervision and penalties

Supervision rests with the national market surveillance authorities; at Union level the Commission's AI Office coordinates, in particular for general-purpose models. The regulation provides tiered fine ranges that, depending on the infringement, attach either to fixed maximum amounts or to a share of worldwide annual turnover; the highest range applies to prohibited practices.

Relationship to data protection and product law

The AI Act displaces neither the GDPR nor existing product safety law. Where personal data is processed, the legal basis, data subject rights and, where applicable, the data protection impact assessment continue to apply unchanged. The workable path therefore begins the same way in both cases: with a complete inventory of the AI systems in use, their intended purpose and the role your own organisation plays in each.

The inventory question before the classification

The AI Act is present in Rizzqo as a taxonomy on the asset model, meaning a structure for classification. The risk classification is a legal judgement.

Before that judgement, though, sits a question many organisations cannot answer: which AI systems are actually in use. Such systems often arise inside business units and appear in neither procurement nor a network scan. In Rizzqo an AI system is therefore an asset like a business process, with the models, data sources, operating environments and providers involved hanging beneath it as supporting objects, each with a named owner. Only with that list can anything be classified.

Browse all entriesBack to top

Frequently asked questions

See compliance run on your real assets

Rizzqo turns framework requirements into owned tasks on the assets you already have, and prices the risk in real money.

Made in GermanyHosted in your countryMulti-framework