Every article of the EU AI Act — explained in plain language. Each entry covers what the article says, who it affects, and what it means specifically for small and medium businesses. Published progressively.
Guide completion
100% (113 of 113 articles)
Filter:
Chapter I
General Provisions
4 articles
Art.
1
1
Article 1 — Subject Matter
What the EU AI Act is, what it regulates, and why it exists
Art.
2
2
Article 2 — Scope of Application
Who the Act applies to — providers, deployers, importers, and more
Art.
3
3
Article 3 — Definitions
The official definitions of AI system, provider, deployer and 60+ other terms
Art.
4
4
Article 4 — AI Literacy
Obligations on providers and deployers to ensure staff understand AI
Chapter II
Prohibited AI Practices
1 article
Chapter III
High-Risk AI Systems
44 articles
Art.
6
6
Article 6 — Classification Rules for High-Risk AI Systems
How to determine if your AI system falls into the high-risk category
Art.
7
7
Article 7 — Amendments to Annex III
How the Commission can expand the high-risk AI list over time
Art.
8
8
Article 8 — Compliance with Requirements for High-Risk AI Systems
The baseline compliance standard all high-risk AI systems must meet
Art.
9
9
Article 9 — Risk Management System
How providers must identify, assess and mitigate risks throughout the AI lifecycle
Art.
10
10
Article 10 — Data and Data Governance
Data quality and governance requirements for training high-risk AI systems
Art.
11
11
Article 11 — Technical Documentation
Technical documentation requirements providers must prepare before market placement
Art.
12
12
Article 12 — Record-Keeping
Automatic logging requirements built into high-risk AI systems
Art.
13
13
Article 13 — Transparency and Provision of Information to Deployers
Providers must supply clear instructions so deployers can use high-risk AI correctly
Art.
14
14
Article 14 — Human Oversight
High-risk AI systems must allow humans to effectively oversee and override them
Art.
15
15
Article 15 — Accuracy, Robustness and Cybersecurity
Technical standards for accuracy, robustness and cybersecurity of high-risk AI
Art.
16
16
Article 16 — Obligations of Providers of High-Risk AI Systems
The complete list of compliance obligations for providers of high-risk AI systems
Art.
17
17
Article 17 — Quality Management System
Providers must implement a formal documented quality management system
Art.
18
18
Article 18 — Documentation Keeping
Providers must keep technical documentation for ten years after market placement
Art.
19
19
Article 19 — Automatically Generated Logs
Providers must retain automatically generated AI system logs for at least six months
Art.
20
20
Article 20 — Corrective Actions and Duty of Information
Providers must immediately act and notify authorities when non-compliance is discovered
Art.
21
21
Article 21 — Cooperation with Competent Authorities
Providers must cooperate with national authorities and provide requested documentation
Art.
22
22
Article 22 — Authorised Representatives of Providers of High-Risk AI Systems
Non-EU providers must appoint an EU-based authorised representative before market entry
Art.
23
23
Article 23 — Obligations of Importers of High-Risk AI Systems
EU importers of high-risk AI must verify compliance before placing systems on the market
Art.
24
24
Article 24 — Obligations of Distributors of High-Risk AI Systems
Distributors must verify CE marking and compliance documentation before making AI available
Art.
25
25
Article 25 — Responsibilities Along the AI Value Chain
When distributors, importers or deployers modify or rebrand AI they become providers
Art.
26
26
Article 26 — Obligations of Deployers of High-Risk AI Systems
The full compliance obligations for businesses that deploy high-risk AI systems
Art.
27
27
Article 27 — Fundamental Rights Impact Assessment for High-Risk AI Systems
Public bodies and certain private deployers must assess fundamental rights impact before first AI use
Art.
28
28
Article 28 — Notifying Authorities
Each EU member state must designate a national authority to oversee conformity assessment bodies
Art.
29
29
Article 29 — Application of a Conformity Assessment Body for Notification
The application process for conformity assessment bodies seeking official AI Act designation
Art.
30
30
Article 30 — Notification Procedure
The formal EU notification procedure for activating notified body designations
Art.
31
31
Article 31 — Requirements Relating to Notified Bodies
The independence, competence and impartiality standards notified bodies must meet
Art.
32
32
Article 32 — Presumption of Conformity with Requirements Relating to Notified Bodies
Bodies accredited to harmonised standards are presumed to meet notified body requirements
Art.
33
33
Article 33 — Subsidiaries of Notified Bodies and Subcontracting
Notified bodies may subcontract assessment work but retain full legal responsibility
Art.
34
34
Article 34 — Operational Obligations of Notified Bodies
How notified bodies must conduct conformity assessments — proportionately and transparently
Art.
35
35
Article 35 — Identification Numbers and Lists of Notified Bodies
The Commission maintains the public NANDO register of all authorised notified bodies
Art.
36
36
Article 36 — Changes to Notifications
Procedures for restricting, suspending or withdrawing notified body designations
Art.
37
37
Article 37 — Challenge to the Competence of Notified Bodies
The Commission can investigate and override notified bodies that fail to meet requirements
Art.
38
38
Article 38 — Coordination of Notified Bodies
Notified bodies must coordinate to ensure consistent AI conformity assessment across the EU
Art.
39
39
Article 39 — Conformity Assessment Bodies of Third Countries
Non-EU assessment bodies can only operate under the AI Act where international agreements permit
Art.
40
40
Article 40 — Harmonised Standards and Standardisation Deliverables
Compliance with published harmonised standards creates a legal presumption of conformity for high-risk AI
Art.
41
41
Article 41 — Common Specifications
Commission-issued technical specifications when harmonised standards are unavailable
Art.
42
42
Article 42 — Presumption of Conformity with Certain Requirements
Specific presumptions of conformity for data quality and cybersecurity-certified AI systems
Art.
43
43
Article 43 — Conformity Assessment
Which conformity assessment procedure applies — self-assessment or notified body involvement
Art.
44
44
Article 44 — Certificates
Notified body certificates are valid for up to five years and can be suspended or withdrawn
Art.
45
45
Article 45 — Information Obligations of Notified Bodies
Notified bodies must report certificates issued, refused and withdrawn to authorities and each other
Art.
46
46
Article 46 — Derogation from Conformity Assessment Procedure
Market surveillance authorities can authorise high-risk AI use before assessment in exceptional circumstances
Art.
47
47
Article 47 — EU Declaration of Conformity
Providers must draw up a formal written declaration that their high-risk AI system is compliant
Art.
48
48
Article 48 — CE Marking
High-risk AI systems must bear the CE marking before being placed on the EU market
Art.
49
49
Article 49 — Registration
Providers must register high-risk AI systems in the EU database before market placement
Chapter IV
Transparency Obligations
1 article
Chapter V
General-Purpose AI Models
6 articles
Art.
51
51
Article 51 — Classification of General-Purpose AI Models as General-Purpose AI Models with Systemic Risk
GPAI models trained with over 10^25 FLOPs are classified as presenting systemic risk
Art.
52
52
Article 52 — Procedure for Classifying GPAI Models with Systemic Risk
The procedure for notifying, challenging and confirming GPAI systemic risk classification
Art.
53
53
Article 53 — Obligations for Providers of General-Purpose AI Models
All GPAI providers must supply technical documentation, respect copyright, and support downstream providers
Art.
54
54
Article 54 — Authorised Representatives of Providers of General-Purpose AI Models
Non-EU GPAI model providers must appoint an EU-based authorised representative
Art.
55
55
Article 55 - Obligations of Providers of General-Purpose AI Models with Systemic Risk
Frontier GPAI model providers must conduct adversarial testing, mitigate systemic risks and report incidents
Art.
56
56
Article 56 - Codes of Practice
GPAI providers can demonstrate compliance with AI Office-approved codes of practice
Chapter VI
Measures in Support of Innovation
7 articles
Art.
57
57
Article 57 - AI Regulatory Sandboxes
Every EU member state must establish an AI regulatory sandbox with priority access for SMEs and startups
Art.
58
58
Article 58 - Detailed Arrangements for, and Functioning of, AI Regulatory Sandboxes
The operational rules for AI sandboxes — selection, plans, safe harbour from penalties, and exit guidance
Art.
59
59
Article 59 - Further Processing of Personal Data for Developing Certain AI Systems in the Public Interest in the AI Regulatory Sandbox
Sandbox participants can process personal data beyond original purpose for public interest AI development
Art.
60
60
Article 60 - Testing of High-Risk AI Systems in Real World Conditions Outside AI Regulatory Sandboxes
Providers may test high-risk AI in real-world conditions outside sandboxes under an approved plan
Art.
61
61
Article 61 - Informed Consent to Participate in Testing in Real World Conditions Outside AI Regulatory Sandboxes
Test subjects in real-world AI trials must give freely-given, documented informed consent beforehand
Art.
62
62
Article 62 - Measures for Providers and Deployers, in Particular SMEs, Including Start-Ups
The Act's dedicated support package for SMEs — priority sandboxes, reduced fees, templates and training
Art.
63
63
Article 63 - Derogations for Specific Operators
Microenterprises may comply with certain quality management requirements in a simplified manner
Chapter VII
Governance
7 articles
Art.
64
64
Article 64 - AI Office
The European AI Office — the Commission's central body for AI governance and GPAI oversight
Art.
65
65
Article 65 - Establishment and Structure of the European Artificial Intelligence Board
The AI Board — one representative per member state, chaired by the Commission, coordinating EU AI governance
Art.
66
66
Article 66 - Tasks of the Board
The AI Board's tasks — advisory opinions, enforcement coordination and standardisation contributions
Art.
67
67
Article 67 - Advisory Forum
The Advisory Forum — industry, SME, civil society and academia advising the AI Board and Commission
Art.
68
68
Article 68 - Scientific Panel of Independent Experts
The Scientific Panel of independent experts — technical oversight of GPAI models with power to trigger systemic risk investigations
Art.
69
69
Article 69 - Access to the Pool of Experts by the Member States
Member states can access the EU Scientific Panel's expert pool to support national AI enforcement
Art.
70
70
Article 70 - Designation of National Competent Authorities and Single Point of Contact
Member states must designate national AI competent authorities and a single point of contact by August 2025
Chapter VIII
EU Database for High-Risk AI Systems
1 article
Chapter IX
Post-Market Monitoring
23 articles
Art.
72
72
Article 72 - Post-Market Monitoring by Providers and Post-Market Monitoring Plan for High-Risk AI Systems
Providers must actively monitor high-risk AI performance throughout its lifetime and document a monitoring plan
Art.
73
73
Article 73 - Reporting of Serious Incidents
Providers must report serious AI incidents within 15 days — or 2 days for severe cases and 10 days for fatalities
Art.
74
74
Article 74 - Market Surveillance and Control of AI Systems in the Union Market
Market surveillance authorities can inspect, investigate and order corrections or withdrawals of non-compliant AI systems
Art.
75
75
Article 75 - Mutual Assistance, Market Surveillance and Control of General-Purpose AI Systems
Market surveillance authorities must assist each other on cross-border cases — with the AI Office leading GPAI oversight
Art.
76
76
Article 76 - Supervision of Testing in Real World Conditions by Market Surveillance Authorities
Market surveillance authorities actively supervise real-world AI testing and may suspend it if risks emerge
Art.
77
77
Article 77 - Powers of Authorities Protecting Fundamental Rights
Market surveillance authorities must cooperate with fundamental rights bodies when AI systems may infringe rights
Art.
78
78
Article 78 - Confidentiality
All parties receiving AI Act information — from authorities to notified bodies — are bound by strict confidentiality
Art.
79
79
Article 79 - Procedure at National Level for Dealing with AI Systems Presenting a Risk
The step-by-step national procedure when an AI system presents a risk — from evaluation to possible market withdrawal
Art.
80
80
Article 80 - Procedure for Dealing with AI Systems Classified by the Provider as Non-High-Risk in Application of Annex III
Authorities can challenge non-high-risk self-assessments — with extra fines for deliberate misclassification
Art.
81
81
Article 81 - Union Safeguard Procedure
The Commission adjudicates contested national AI enforcement measures — with binding decisions within six months
Art.
82
82
Article 82 - Compliant AI Systems Which Present a Risk
Authorities can require corrective action even for fully compliant AI systems that still present a risk
Art.
83
83
Article 83 - Formal Non-Compliance
Authorities enforce specific formal failures — missing CE marking, incorrect declarations, absent registration or representative
Art.
84
84
Article 84 - Union AI Testing Support Structures
The Commission must designate Union AI testing support structures to provide technical assessment capacity to enforcement authorities
Art.
85
85
Article 85 - Right to Lodge a Complaint with a Market Surveillance Authority
Anyone may lodge a formal complaint with a market surveillance authority about suspected AI Act violations
Art.
86
86
Article 86 - Right to Explanation of Individual Decision-Making
Individuals significantly affected by high-risk AI decisions have the right to a clear and meaningful explanation
Art.
87
87
Article 87 - Reporting of Infringements and Protection of Reporting Persons
Persons reporting AI Act violations in good faith are protected from retaliation under EU whistleblower law
Art.
88
88
Article 88 - Enforcement of the Obligations of Providers of General-Purpose AI Models
The AI Office is the exclusive enforcement authority for GPAI provider obligations — with investigation, evaluation and measure powers
Art.
89
89
Article 89 - Monitoring Actions
The AI Office continuously monitors GPAI provider compliance — separate from formal investigations
Art.
90
90
Article 90 - Alerts of Systemic Risks by the Scientific Panel
The Scientific Panel can issue qualified alerts to the AI Office about specific GPAI models presenting systemic risks
Art.
91
91
Article 91 - Power to Request Documentation and Information
The AI Office can compel GPAI providers to produce documentation, data, source code and model access on request
Art.
92
92
Article 92 - Power to Conduct Evaluations
The AI Office can directly test and evaluate GPAI models to assess compliance and systemic risks
Art.
93
93
Article 93 - Power to Request Measures
The AI Office can impose binding corrective measures on GPAI providers — up to and including market withdrawal
Art.
94
94
Article 94 - Procedural Rights of Economic Operators of the General-Purpose AI Model
GPAI providers have the right to be heard, access the enforcement file and seek legal representation before adverse decisions
Chapter X
Codes of Conduct and Guidelines
2 articles
Art.
95
95
Article 95 - Codes of Conduct for Voluntary Application of Specific Requirements
Non-high-risk AI providers may voluntarily adopt high-risk standards through Commission-approved codes of conduct
Art.
96
96
Article 96 - Guidelines from the Commission on the Implementation of this Regulation
The Commission must issue AI Act implementation guidelines — with SME needs explicitly required to be taken into account
Chapter XI
Delegation of Power and Committee Procedure
2 articles
Art.
97
97
Article 97 - Exercise of the Delegation
The Commission has five-year renewable power to adopt delegated acts updating technical AI Act requirements
Art.
98
98
Article 98 - Committee Procedure
The Commission adopts AI Act implementing acts with member state committee oversight — covering templates, specifications and procedures
Chapter XII
Penalties
3 articles
Art.
99
99
Article 99 - Penalties
AI Act fines reach EUR 35 million or 7% of global turnover — with proportionality protection for SMEs built in
Art.
100
100
Article 100 - Administrative Fines on Union Institutions, Bodies, Offices and Agencies
EU institutions are subject to AI Act fines imposed by the European Data Protection Supervisor
Art.
101
101
Article 101 - Fines for Providers of General-Purpose AI Models
GPAI providers face fines up to EUR 15 million or 3% of global turnover — plus daily penalties for persistent non-compliance
Chapter XIII
Final Provisions
12 articles
Art.
102
102
Article 102 - Amendment to Regulation (EC) No 300/2008
Civil aviation security regulation amended to integrate AI Act requirements for AI systems used in aviation screening
Art.
103
103
Article 103 - Amendment to Regulation (EU) No 167/2013
Agricultural and forestry vehicle regulation amended to integrate AI Act requirements for AI systems in machinery
Art.
104
104
Article 104 - Amendment to Regulation (EU) No 168/2013
Two- and three-wheel vehicle regulation amended to integrate AI Act requirements for AI systems in motorcycles and mopeds
Art.
105
105
Article 105 - Amendment to Directive 2014/90/EU
Marine equipment directive amended to integrate AI Act requirements for AI systems in shipboard safety equipment
Art.
106
106
Article 106 - Amendment to Directive (EU) 2016/797
Rail interoperability directive amended to integrate AI Act requirements for AI systems in railway operations
Art.
107
107
Article 107 - Amendment to Regulation (EU) 2018/858
Motor vehicle type-approval regulation amended to integrate AI Act requirements for AI systems in cars, vans and trucks
Art.
108
108
Article 108 - Amendments to Regulation (EU) 2018/1139
EU aviation safety regulation amended to integrate AI Act requirements for aircraft, drones and air traffic management AI systems
Art.
109
109
Article 109 - Amendment to Regulation (EU) 2019/2144
Motor vehicle general safety regulation amended to integrate AI Act requirements for AI-powered ADAS and safety systems
Art.
110
110
Article 110 - Amendment to Directive (EU) 2020/1828
Consumer organisations can bring collective redress actions for AI Act violations harming consumers' collective interests
Art.
111
111
Article 111 - AI Systems Already Placed on the Market or Put into Service
AI systems already deployed before the Act's application dates benefit from transitional protection — with important exceptions
Art.
112
112
Article 112 - Evaluation and Review
The Commission must evaluate the Act's effectiveness every four years — with a dedicated 2028 review of its impact on SMEs
Art.
113
113
Article 113 - Entry into Force and Application
Updated by the Digital Omnibus: prohibited practices Feb 2025, GPAI Aug 2025, Annex III high-risk Dec 2027, Annex I Aug 2028
