Framework
EU AI Act
The Union law on artificial intelligence: risk tiers, roles, and the obligations that follow from them. Each page sets out what a provision requires, who it binds, when it applies, and what evidence discharges it.
§ 1 — Orientation
How the Act is put together
The Act does not regulate artificial intelligence in general. It regulates particular uses of it, sorted into tiers, and almost everything that follows turns on which tier a system lands in and which role you occupy in relation to it. A system that is prohibited under Article 5 cannot be placed on the market at all. A system that is high-risk — because it appears in Annex III, or because it is a safety component of a product already regulated under Annex I — carries the obligations set out in Articles 8 to 17 for its provider and Article 26 for its deployer. Everything else carries transparency duties at most.
The role question is the one organisations get wrong most often, and it is not a matter of self-description. A company that buys a model, puts its own name on it and sells it on is a provider, not a deployer, and inherits the provider obligations wholesale under Article 25(1). So does one that substantially modifies a high-risk system. Reading these pages, the first question to settle is not what the article requires but whether it requires it of you.
The obligations below are the ones that generate assurance work: something has to be built, evidenced, and capable of being shown to someone who did not build it. For each, these pages state the provision, who it binds, when it applies, and the artefacts an assessor asks for — which is the part the Regulation itself never sets out, because it specifies outcomes and leaves the evidence to practice.
§ 2 — By who it binds
Obligations by role
On the provider
Whoever develops the system, or places it on the market under their own name — including a deployer that rebrands or substantially modifies one.
- Article 9Risk management system
Article 9 requires a risk management system that runs continuously across the whole lifecycle of a high-risk AI system, not a document produced once before launch.
- Article 15Accuracy, robustness and cybersecurity
Article 15 requires an appropriate level of accuracy, robustness and cybersecurity, held consistently across the lifecycle.
On the deployer
Whoever uses the system under their own authority, in the course of their activity.
- Article 26Obligations of deployers of high-risk AI systems
Article 26 is the deployer’s article.
- Article 27Fundamental rights impact assessment for high-risk AI systems
Article 27 obliges certain deployers to assess the impact on fundamental rights before putting a high-risk system into use, and to notify the market surveillance authority of the result.
§ 3 — By when it applies
Obligations by date
The date each obligation first bites, earliest first. Where a provision applies on more than one date, the earliest is shown.