Regulation (EU) 2024/1689 (EU Artificial Intelligence Act)

EU AI Act — Implementation Guide for Providers and Deployers of AI Systems

Structured readiness for artificial intelligence: risk classification (Art. 6 & Annex III), prohibited practices (Art. 5), transparency obligations (Art. 50), and GPAI governance overview.

Official EU Regulatory Compliance Center

Comprehensive knowledge base and requirements analysis for the EU Artificial Intelligence Act (Regulation (EU) 2024/1689). Verify risk classification, GPAI rules, and transparency obligations.

AIActSteps is an independent informational and scoping portal by SKOPION Intelligence. Not legal advice under national legal counseling acts. AI risk classification requires individualized assessment.

AIActSteps is the specialized guidance portal for the SKOPION service AI Security Audit & AI Act Readiness

What Does the EU AI Act Regulate?

Regulation (EU) 2024/1689 establishes a harmonized European legal framework for trustworthy, transparent, and safe artificial intelligence.

Who is covered?

Providers developing or marketing AI systems under their own brand, and commercial or public deployers operating AI systems within the European Union. Excluded are systems used exclusively for military, defence, or pure research purposes.

What does it require?

Risk-tiered obligations: strict prohibition of unacceptable practices (Art. 5), quality management, risk assessment, and human oversight for high-risk AI (Art. 9–15), and transparency rules for generative AI (Art. 50).

Transparency & Labeling

Transparency obligations under Article 50 (mandatory from 2 August 2026): informing natural persons when interacting with AI systems (e.g. chatbots), machine-readable marking and detectability of synthetic outputs (audio, image, video / deepfakes), and exposure notifications for emotion recognition or biometric categorisation systems.

General-Purpose AI (GPAI) Models

Rules for general-purpose AI (GPAI) models under Chapter V (Articles 51–56, applicable since 2 August 2025): technical documentation, downstream integration information, EU copyright compliance, and training content summaries using the AI Office template (Art. 53). Training compute exceeding 10^25 FLOPs triggers a statutory presumption of systemic risk.

What Penalties Apply for Violations?

Violations of prohibited AI practices risk fines up to €35 million or 7% of worldwide annual turnover. Non-compliance with high-risk obligations risks up to €15 million or 3% (Art. 99).

How Does Preparation for the EU AI Act Work?

1. AI Inventory & Scoping

Catalog all internal and external AI models, algorithms, and third-party tools to establish whether you act as a provider or deployer.

2. Risk Classification

Determine whether systems trigger prohibited practices (Art. 5), high-risk classification (Annex III or Annex I), or transparency duties (Art. 50).

3. Governance & AI Literacy

Establish continuous risk management procedures and take measures to support the development of a sufficient level of AI literacy among relevant staff and persons dealing with AI systems pursuant to Article 4.

4. Technical Dossier & Conformity

Prepare technical documentation (Annex IV), automatic logging mechanisms, fundamental rights impact assessments, and EU database registration.

What You Gain with AIActSteps

Risk Scoping & Classification

Clear determination whether your systems qualify as high-risk, transparency-only, or minimal-risk AI applications.

Timeline & Action Roadmap

Comprehensive mapping of applicable statutory milestones from 2025 to 2028 based on your specific system profile.

Audit-Readiness for Steps Core

Structured technical preparation for automated self-assessment and compliance evidence management in Steps Core.

EU AI Act Architecture at a Glance

The forthcoming CODEX Steps Core assessment engine will systematically map the risk-tiered requirements of Regulation (EU) 2024/1689:

1. Prohibited AI Practices (Art. 5 — Active 02 Feb 2025)

Strict screening of banned practices: prohibitions on social scoring, real-time remote biometric identification in public spaces, cognitive manipulation, and workplace emotion recognition.

2. GPAI & Foundation Models (Art. 51–56 — Active 02 Aug 2025)

Governance and documentation rules for general-purpose AI models, including systemic risk mitigation for models trained above 10^25 FLOPs.

3. Transparency Duties (Art. 50 — Active 02 Aug 2026)

Notification of AI interactions, machine-readable watermarking for synthetic media (deepfakes), and disclosure of AI-generated text.

4. High-Risk AI Systems (Annex III & I — Active 2026/2027)

Continuous risk management system (Art. 9), data governance (Art. 10), technical documentation (Annex IV), automated logging (Art. 12), and human oversight (Art. 14).

Independent Methodology & Guidance

Our preparation framework aligns strictly with Regulation (EU) 2024/1689, European AI Office guidance, and national supervisory standards. We assist developers and deployers in early compliance readiness.

Applicable across the European Economic Area (EEA).

European Legal Framework for AI

The EU AI Act represents the world's first comprehensive horizontal legal framework for artificial intelligence, establishing global benchmarks for human-centric, trustworthy AI.

Frequently Asked Questions about the EU AI Act

When does the EU AI Act take effect?

Regulation (EU) 2024/1689 entered into force on 1 August 2024. Prohibited AI practices (Art. 5) and AI literacy rules (Art. 4) apply as of 2 February 2025. Rules for general-purpose AI models (GPAI, Articles 51–56) apply from 2 August 2025. General provisions and Article 50 transparency apply from 2 August 2026. Annex III high-risk use cases apply from 2 December 2027; Annex I embedded high-risk systems apply from 2 August 2028.

What is the distinction between Providers and Deployers?

A provider develops an AI system or has it developed to place it on the market under its own name. A deployer uses an AI system under its authority in a professional context. Both roles carry distinct statutory obligations under the AI Act.

Which AI systems qualify as 'High-Risk'?

High-risk AI systems comprise standalone use cases listed in Annex III (applicable from 2 December 2027, e.g. biometrics, critical infrastructure, employment, credit scoring) and safety components in regulated EU harmonised products listed in Annex I (applicable from 2 August 2028, e.g. medical devices, machinery, vehicles).

What is required under the Article 4 AI Literacy duty?

Under Article 4, providers and deployers of AI systems must take measures to support the development of a sufficient level of AI literacy among their staff and other persons dealing with the operation and use of AI systems on their behalf, taking into account their technical role and operational context.

How does the AI Act differ from CRA and NIS2?

NIS2 governs organizational cyber resilience. CRA regulates hardware/software product security. The AI Act specifically regulates AI trustworthiness, transparency, and safety.

Dedicated Implementation Path & AI Act Audit

Verify your artificial intelligence systems under the EU AI Act. Clarify risk classification, GPAI duties, and transparency requirements with SKOPION Intelligence auditors.

Your data is handled confidentially pursuant to our Privacy Policy.