The AI Act is a product-safety law, passed in 2024. It regulates AI by the risk of its use, sorting systems into four tiers with escalating duties. Penalties reach €35M or 7% of global turnover. The rules phase in through 2028, but the 2026 Digital Omnibus Regulation just pushed back the timeline for high-risk uses.
The Act assigns duties by what an AI system is used for, in proportion to the risk that use poses to health, safety, and fundamental rights. The underlying technology rarely matters. The same model, whether a vision network or a large language model, can sit in any tier depending on how it is deployed.
Classification drives everything else. Once a use falls into a tier, the bans, the obligations, and the fines all follow from that placement. General-purpose AI models get a parallel regime on top, because a single model feeds many downstream uses at once.
Each use falls into one of four tiers, and the duty rises with the tier: outright prohibition, a full compliance regime, a light disclosure rule, or nothing at all.
Click each for what it covers and its core obligations.
Eight real deployments, sorted by the Act's logic. Select one to see its tier, why it falls there, and the duties that follow.
Illustrative routing of the statutory logic — not legal advice. Edge cases (e.g. high-risk exemptions under Art 6(3)) need the full text.
Article 5 prohibits a short list of uses deemed incompatible with EU rights. The original list has been enforceable since 2 February 2025 and carries the top fine; the Digital Omnibus adds one more ban, effective 2 December 2026.
High-risk systems are legal, but they carry the Act's full compliance regime. A system arrives here by one of two routes.
AI embedded in products already covered by EU product-safety law, assessed through those existing regimes.
Systems whose use bears directly on people's rights, safety, or access to essential services.
Every high-risk system carries the same nine obligations, but the work each one demands varies by system. Pick one to see each duty turned into concrete steps.
Using a high-risk system carries its own duties. Public bodies and certain private deployers must run a Fundamental Rights Impact Assessment before first use, register the deployment in the EU database, keep meaningful human oversight in live operation, and inform the people subject to it.
Some uses are low-stakes but can deceive, so the Act adds only a transparency duty (Article 50), applying from 2 August 2026:
Systems already on the market before 2 August 2026 have until 2 December 2026 to meet the machine-readable marking duty (Article 50(2)); systems placed on the market after that date must comply immediately.
Everything else — spam filters, recommender systems, inventory optimisation, AI in video games — sits in minimal risk and carries no obligations under the Act. This is the vast majority of AI in use.
AI-literacy duties (Article 4) apply to providers and deployers across all tiers, in force since 2 February 2025: staff using AI must have adequate understanding of it.
Foundation models do not fit the use-based tiers, because one model feeds thousands of downstream uses. The Act governs them directly, with rules live since 2 August 2025.
Every GPAI model owes baseline transparency: technical documentation for the AI Office and downstream providers, a policy to respect EU copyright, and a public summary of training-data sources.
A model crosses into systemic risk when its training compute exceeds 10²⁵ FLOPs (a rebuttable presumption of high-impact capability). The frontier labs sit here.
Model evaluations and adversarial red-teaming · serious-incident reporting to the AI Office · state-of-the-art cybersecurity · systemic-risk assessment and mitigation. Backed by a GPAI Code of Practice.
Fines scale with the violation and are the higher of a fixed cap or a percentage of global annual turnover. Drag your turnover to see which cap applies.
For SMEs and start-ups the cap is the lower of the two figures, not the higher.
Drawn to scale across 2024–2028. The 2026 Digital Omnibus (provisional deal 7 May 2026, Parliament endorsed 16 June 2026) pushed the heavy high-risk duties well to the right.