What is the AI Act?
The Artificial Intelligence Act was published in the Official Journal of the EU on 12 July 2024 and entered into force on 1 August 2024. As a regulation it applies directly in every member state — with no national implementation needed — and its scope is extraterritorial: it also covers providers outside the EU when their AI systems, or those systems’ outputs, are used within the Union.
The regulation takes a risk-based approach: the greater the risk to health, safety and fundamental rights, the stricter the requirements. Supervision lies with national market surveillance authorities and — for general-purpose AI models — the AI Office at the European Commission, supported by the European Artificial Intelligence Board.
Risk classification: four tiers plus GPAI
Every AI system must be assigned to one of the risk categories — all further obligations depend on this classification. A separate regime covers general-purpose AI (GPAI) models, such as large language models, which can power many different systems.
- Unacceptable risk (Article 5) — prohibited practices: subliminal manipulation, exploiting people’s vulnerabilities, social scoring, predicting criminality based solely on profiling, untargeted scraping of facial images from the internet, emotion recognition in the workplace and education, real-time remote biometric identification in public spaces (with narrow law enforcement exceptions).
- High risk (Article 6, Annex III) — for example AI in recruitment and workforce management, credit scoring, education, critical infrastructure, biometrics, access to public services, the administration of justice. Permitted, but under the strict Articles 9-15 requirements and conformity assessment.
- Limited risk (Article 50) — transparency duties: chatbots must disclose they are AI; synthetic content and deepfakes must be labelled.
- Minimal risk — the vast majority of uses (spam filters, AI in games, recommender systems); no new obligations, voluntary codes of conduct encouraged.
- GPAI models (Articles 51-56) — technical documentation, information for downstream integrators, a copyright policy and a training data summary; models with systemic risk (the 10^25 FLOPS training threshold) additionally: model evaluations, adversarial testing, serious incident reporting and cybersecurity.
Who does it apply to, and in which role?
The AI Act distinguishes roles in the AI value chain and assigns different duties to each. The heaviest burden falls on the provider — the entity that develops an AI system and places it on the market under its own name. The deployer — any company or institution using AI in its operations — is responsible, among other things, for use in line with the instructions, human oversight, relevant input data and informing affected people. Importers and distributors verify that the systems they bring to market carry the required documentation and markings.
An important practical trap: a deployer that puts its own brand on a high-risk system or substantially modifies it (for example significantly fine-tuning a purchased model for a new purpose) assumes the provider’s full obligations. Classification follows the use case, not the technology — the same language model used as a marketing chatbot triggers only transparency duties, while used for CV screening it creates a high-risk system.
High-risk system requirements (Articles 9-15)
The core of the regulation is a set of seven requirements for high-risk systems, which the provider must satisfy before placing the system on the market and maintain across its lifecycle — confirmed by conformity assessment, an EU declaration of conformity, CE marking and registration in the public EU database.
- A risk management system (Article 9) — a continuous, iterative process across the system’s lifecycle.
- Data governance (Article 10) — relevant, representative training, validation and test datasets, examined for bias.
- Technical documentation (Article 11, Annex IV) — complete and current, ready to submit to an authority.
- Record-keeping (Article 12) — automatic logs enabling reconstruction of the system’s operation.
- Transparency and information for deployers (Article 13) — instructions covering intended purpose, accuracy and limitations.
- Human oversight (Article 14) — a genuine ability to disregard, halt or reverse the system’s output.
- Accuracy, robustness and cybersecurity (Article 15) — declared metrics plus resilience against errors and AI-specific attacks.
Application timeline 2025-2027
The regulation entered into force on 1 August 2024, but its provisions apply in stages. Some obligations are already binding — and enforceable.
- 2 February 2025 — the AI practice prohibitions (Article 5) and the AI literacy duty (Article 4).
- 2 August 2025 — GPAI model obligations, designation of supervisory authorities, the penalty provisions.
- 2 August 2026 — the bulk of the regulation, including the Annex III high-risk requirements and the Article 50 transparency duties.
- 2 August 2027 — high-risk systems that are components of products covered by EU harmonisation legislation (Annex I, for example medical devices, machinery), and the end of the transition period for GPAI models placed on the market before August 2025.
Penalties and enforcement
The AI Act sets three tiers of administrative fines, calculated as a fixed amount or a percentage of the company’s total worldwide annual turnover — whichever is higher. Engaging in the Article 5 prohibited practices carries fines of up to EUR 35 million or 7% of turnover. Breaching most other obligations (including the high-risk requirements and transparency duties) — up to EUR 15 million or 3% of turnover. Supplying incorrect, incomplete or misleading information to authorities — up to EUR 7.5 million or 1% of turnover. For SMEs and startups the lower of the two values applies.
Beyond fines, market surveillance authorities can demand documentation, order corrective actions and ultimately withdraw a system from the market. In practice pressure also comes from the market itself: corporate customers and the public sector already put AI Act compliance into procurement questionnaires and contracts, just as happened earlier with GDPR.
How does Guardiso help?
Guardiso turns the AI Act into a working compliance programme — from AI system inventory and classification, through obligations mapped to roles and deadlines, to inspection-ready evidence.
- An AI system register with AI Act risk classification and the organisation’s role (provider / deployer) assigned per system.
- AI Act controls seeded automatically when you enable the standard — from the Article 5 prohibitions, through the Articles 9-15 requirements, to GPAI and post-market monitoring.
- An AI policy, acceptable use rules and FRIA (fundamental rights impact assessment) templates generated and versioned in the platform.
- An AI risk register (bias, model drift, security, intellectual property) linked to controls and treatment plans.
- Recurring tasks guarding the deadlines: classification reviews, AI literacy training, technical documentation updates, human oversight tests.
- An evidence repository for the supervisory authority or your customers: technical documentation, logs, declarations of conformity, training records — in one place.
- Cross-mapping to ISO/IEC 42001, ISO 27001 and GDPR — an AI management system built once satisfies the overlapping requirements of multiple frameworks.
