Regulations · AI Act

EU AI Act

Regulation (EU) 2024/1689EU AI Act (Regulation 2024/1689) applies to AI systems on the EU market. Prohibited practices from February 2025, GPAI obligations August 2025, high-risk systems August 2026. Free risk-classification.

Days until enforcement
1days
Atomic obligations
33
Max exposure
€35M
or 7% global turnover

Who is concerned?

The AI Act applies to any AI system placed on the EU market or used by EU-located deployers, regardless of where the provider is based.

  • Providers of high-risk AI systems (Annex III : biometric ID, critical infrastructure management, education, employment, essential services, law enforcement, migration, justice, democratic processes)
  • Deployers of high-risk AI systems — companies using high-risk AI for their operations
  • General-purpose AI providers (GPAI) — including foundation models with systemic risk
  • Limited-risk AI providers — subject to transparency obligations (chatbots, deepfakes)

What it requires (high-level)

  • Risk tier classification : unacceptable (banned), high-risk, limited-risk, minimal-risk.
  • High-risk obligations : risk management system, data governance, technical documentation, record-keeping, transparency, human oversight, accuracy/robustness/cybersecurity.
  • Fundamental Rights Impact Assessment (FRIA, Art. 27) — for high-risk AI in public services.
  • GPAI provider obligations : technical documentation, copyright compliance, transparency about training data summary.
  • Systemic risk obligations : additional model evaluation, adversarial testing, incident reporting.

Penalty exposure

  • €35M or 7% of global annual turnover for prohibited practices.
  • €15M or 3% for high-risk non-compliance.
  • €7.5M or 1% for incorrect information to authorities.

Highest penalty regime in the EU regulatory landscape.

How NexCyber helps with AI Act

  • Risk tier classifier — input your AI system specs, get classification + obligations checklist.
  • FRIA template — guided assessment for high-risk public-service deployers.
  • GPAI transparency dossier — training data summary, copyright compliance documentation.
  • EU AI Office reporting — pre-filled templates for systemic risk evaluations.

The clock : AI Act prohibitions in force since 2 Feb 2025. GPAI obligations from 2 Aug 2026. Full high-risk obligations from 2 Aug 2027.

AI Act — Frequently asked questions

Is my AI system high-risk under the EU AI Act?+

High-risk AI systems are listed in Annex III and include AI used in biometrics, critical infrastructure, education, employment, essential services, law enforcement, migration, justice and democratic processes — plus AI as safety component of products covered by EU harmonisation legislation (medical devices, machinery, toys, etc.). Run the free risk classifier at nexcyber.eu/tools/ai-act-risk-classifier.

When do AI Act obligations kick in?+

Prohibited AI practices banned from 2 February 2025. General-purpose AI model (GPAI) obligations from 2 August 2025. High-risk AI systems must comply by 2 August 2026 (or 2027 for AI embedded in regulated products). Penalties are enforceable from August 2026.

What does Article 53 require for GPAI providers?+

Providers of general-purpose AI models must maintain up-to-date technical documentation, provide information to downstream providers integrating the model, comply with the EU Copyright Directive, and publish a sufficiently detailed summary of the training data. Models with systemic risk additionally face Article 55 obligations.

What penalties apply under the AI Act?+

Up to €35 million or 7% of worldwide annual turnover for the most serious breaches (prohibited practices). €15M/3% for breaches of obligations for providers, deployers, importers, distributors. €7.5M/1% for incorrect information to notifying bodies and authorities. SMEs and start-ups benefit from proportionate caps.

See your AI Act readiness in 5 minutes.

Free assessment. No credit card. EU-hosted. Auditable engine.

Run free assessment