EU AI Act Guide: Article by Article

Every article of the EU AI Act — explained in plain language. Each entry covers what the article says, who it affects, and what it means specifically for small and medium businesses. Published progressively.

Guide completion
100%  (113 of 113 articles)
Filter:
Chapter III High-Risk AI Systems 44 articles
Art.
6
Article 6 — Classification Rules for High-Risk AI Systems
How to determine if your AI system falls into the high-risk category
High-Risk
Art.
7
Article 7 — Amendments to Annex III
How the Commission can expand the high-risk AI list over time
Governance
Art.
8
Article 8 — Compliance with Requirements for High-Risk AI Systems
The baseline compliance standard all high-risk AI systems must meet
High-Risk
Art.
9
Article 9 — Risk Management System
How providers must identify, assess and mitigate risks throughout the AI lifecycle
High-Risk
Art.
10
Article 10 — Data and Data Governance
Data quality and governance requirements for training high-risk AI systems
High-Risk
Art.
11
Article 11 — Technical Documentation
Technical documentation requirements providers must prepare before market placement
High-Risk
Art.
12
Article 12 — Record-Keeping
Automatic logging requirements built into high-risk AI systems
High-Risk
Art.
13
Article 13 — Transparency and Provision of Information to Deployers
Providers must supply clear instructions so deployers can use high-risk AI correctly
High-Risk
Art.
14
Article 14 — Human Oversight
High-risk AI systems must allow humans to effectively oversee and override them
High-Risk
Art.
15
Article 15 — Accuracy, Robustness and Cybersecurity
Technical standards for accuracy, robustness and cybersecurity of high-risk AI
High-Risk
Art.
16
Article 16 — Obligations of Providers of High-Risk AI Systems
The complete list of compliance obligations for providers of high-risk AI systems
High-Risk
Art.
17
Article 17 — Quality Management System
Providers must implement a formal documented quality management system
High-Risk
Art.
18
Article 18 — Documentation Keeping
Providers must keep technical documentation for ten years after market placement
High-Risk
Art.
19
Article 19 — Automatically Generated Logs
Providers must retain automatically generated AI system logs for at least six months
High-Risk
Art.
20
Article 20 — Corrective Actions and Duty of Information
Providers must immediately act and notify authorities when non-compliance is discovered
High-Risk
Art.
21
Article 21 — Cooperation with Competent Authorities
Providers must cooperate with national authorities and provide requested documentation
High-Risk
Art.
22
Article 22 — Authorised Representatives of Providers of High-Risk AI Systems
Non-EU providers must appoint an EU-based authorised representative before market entry
Governance
Art.
23
Article 23 — Obligations of Importers of High-Risk AI Systems
EU importers of high-risk AI must verify compliance before placing systems on the market
Governance
Art.
24
Article 24 — Obligations of Distributors of High-Risk AI Systems
Distributors must verify CE marking and compliance documentation before making AI available
Governance
Art.
25
Article 25 — Responsibilities Along the AI Value Chain
When distributors, importers or deployers modify or rebrand AI they become providers
SME Key
Art.
26
Article 26 — Obligations of Deployers of High-Risk AI Systems
The full compliance obligations for businesses that deploy high-risk AI systems
SME Key
Art.
27
Article 27 — Fundamental Rights Impact Assessment for High-Risk AI Systems
Public bodies and certain private deployers must assess fundamental rights impact before first AI use
High-Risk
Art.
28
Article 28 — Notifying Authorities
Each EU member state must designate a national authority to oversee conformity assessment bodies
Governance
Art.
29
Article 29 — Application of a Conformity Assessment Body for Notification
The application process for conformity assessment bodies seeking official AI Act designation
Governance
Art.
30
Article 30 — Notification Procedure
The formal EU notification procedure for activating notified body designations
Governance
Art.
31
Article 31 — Requirements Relating to Notified Bodies
The independence, competence and impartiality standards notified bodies must meet
Governance
Art.
32
Article 32 — Presumption of Conformity with Requirements Relating to Notified Bodies
Bodies accredited to harmonised standards are presumed to meet notified body requirements
Governance
Art.
33
Article 33 — Subsidiaries of Notified Bodies and Subcontracting
Notified bodies may subcontract assessment work but retain full legal responsibility
Governance
Art.
34
Article 34 — Operational Obligations of Notified Bodies
How notified bodies must conduct conformity assessments — proportionately and transparently
Governance
Art.
35
Article 35 — Identification Numbers and Lists of Notified Bodies
The Commission maintains the public NANDO register of all authorised notified bodies
Governance
Art.
36
Article 36 — Changes to Notifications
Procedures for restricting, suspending or withdrawing notified body designations
Governance
Art.
37
Article 37 — Challenge to the Competence of Notified Bodies
The Commission can investigate and override notified bodies that fail to meet requirements
Governance
Art.
38
Article 38 — Coordination of Notified Bodies
Notified bodies must coordinate to ensure consistent AI conformity assessment across the EU
Governance
Art.
39
Article 39 — Conformity Assessment Bodies of Third Countries
Non-EU assessment bodies can only operate under the AI Act where international agreements permit
Governance
Art.
40
Article 40 — Harmonised Standards and Standardisation Deliverables
Compliance with published harmonised standards creates a legal presumption of conformity for high-risk AI
High-Risk
Art.
41
Article 41 — Common Specifications
Commission-issued technical specifications when harmonised standards are unavailable
High-Risk
Art.
42
Article 42 — Presumption of Conformity with Certain Requirements
Specific presumptions of conformity for data quality and cybersecurity-certified AI systems
High-Risk
Art.
43
Article 43 — Conformity Assessment
Which conformity assessment procedure applies — self-assessment or notified body involvement
High-Risk
Art.
44
Article 44 — Certificates
Notified body certificates are valid for up to five years and can be suspended or withdrawn
High-Risk
Art.
45
Article 45 — Information Obligations of Notified Bodies
Notified bodies must report certificates issued, refused and withdrawn to authorities and each other
Governance
Art.
46
Article 46 — Derogation from Conformity Assessment Procedure
Market surveillance authorities can authorise high-risk AI use before assessment in exceptional circumstances
Governance
Art.
47
Article 47 — EU Declaration of Conformity
Providers must draw up a formal written declaration that their high-risk AI system is compliant
High-Risk
Art.
48
Article 48 — CE Marking
High-risk AI systems must bear the CE marking before being placed on the EU market
High-Risk
Art.
49
Article 49 — Registration
Providers must register high-risk AI systems in the EU database before market placement
High-Risk
Chapter IX Post-Market Monitoring 23 articles
Art.
72
Article 72 - Post-Market Monitoring by Providers and Post-Market Monitoring Plan for High-Risk AI Systems
Providers must actively monitor high-risk AI performance throughout its lifetime and document a monitoring plan
High-Risk
Art.
73
Article 73 - Reporting of Serious Incidents
Providers must report serious AI incidents within 15 days — or 2 days for severe cases and 10 days for fatalities
High-Risk
Art.
74
Article 74 - Market Surveillance and Control of AI Systems in the Union Market
Market surveillance authorities can inspect, investigate and order corrections or withdrawals of non-compliant AI systems
Governance
Art.
75
Article 75 - Mutual Assistance, Market Surveillance and Control of General-Purpose AI Systems
Market surveillance authorities must assist each other on cross-border cases — with the AI Office leading GPAI oversight
Governance
Art.
76
Article 76 - Supervision of Testing in Real World Conditions by Market Surveillance Authorities
Market surveillance authorities actively supervise real-world AI testing and may suspend it if risks emerge
Governance
Art.
77
Article 77 - Powers of Authorities Protecting Fundamental Rights
Market surveillance authorities must cooperate with fundamental rights bodies when AI systems may infringe rights
Governance
Art.
78
Article 78 - Confidentiality
All parties receiving AI Act information — from authorities to notified bodies — are bound by strict confidentiality
Governance
Art.
79
Article 79 - Procedure at National Level for Dealing with AI Systems Presenting a Risk
The step-by-step national procedure when an AI system presents a risk — from evaluation to possible market withdrawal
Governance
Art.
80
Article 80 - Procedure for Dealing with AI Systems Classified by the Provider as Non-High-Risk in Application of Annex III
Authorities can challenge non-high-risk self-assessments — with extra fines for deliberate misclassification
High-Risk
Art.
81
Article 81 - Union Safeguard Procedure
The Commission adjudicates contested national AI enforcement measures — with binding decisions within six months
Governance
Art.
82
Article 82 - Compliant AI Systems Which Present a Risk
Authorities can require corrective action even for fully compliant AI systems that still present a risk
Governance
Art.
83
Article 83 - Formal Non-Compliance
Authorities enforce specific formal failures — missing CE marking, incorrect declarations, absent registration or representative
High-Risk
Art.
84
Article 84 - Union AI Testing Support Structures
The Commission must designate Union AI testing support structures to provide technical assessment capacity to enforcement authorities
Governance
Art.
85
Article 85 - Right to Lodge a Complaint with a Market Surveillance Authority
Anyone may lodge a formal complaint with a market surveillance authority about suspected AI Act violations
Governance
Art.
86
Article 86 - Right to Explanation of Individual Decision-Making
Individuals significantly affected by high-risk AI decisions have the right to a clear and meaningful explanation
High-Risk
Art.
87
Article 87 - Reporting of Infringements and Protection of Reporting Persons
Persons reporting AI Act violations in good faith are protected from retaliation under EU whistleblower law
Governance
Art.
88
Article 88 - Enforcement of the Obligations of Providers of General-Purpose AI Models
The AI Office is the exclusive enforcement authority for GPAI provider obligations — with investigation, evaluation and measure powers
GPAI Models
Art.
89
Article 89 - Monitoring Actions
The AI Office continuously monitors GPAI provider compliance — separate from formal investigations
GPAI Models
Art.
90
Article 90 - Alerts of Systemic Risks by the Scientific Panel
The Scientific Panel can issue qualified alerts to the AI Office about specific GPAI models presenting systemic risks
GPAI Models
Art.
91
Article 91 - Power to Request Documentation and Information
The AI Office can compel GPAI providers to produce documentation, data, source code and model access on request
GPAI Models
Art.
92
Article 92 - Power to Conduct Evaluations
The AI Office can directly test and evaluate GPAI models to assess compliance and systemic risks
GPAI Models
Art.
93
Article 93 - Power to Request Measures
The AI Office can impose binding corrective measures on GPAI providers — up to and including market withdrawal
GPAI Models
Art.
94
Article 94 - Procedural Rights of Economic Operators of the General-Purpose AI Model
GPAI providers have the right to be heard, access the enforcement file and seek legal representation before adverse decisions
GPAI Models
Chapter XIII Final Provisions 12 articles
Art.
102
Article 102 - Amendment to Regulation (EC) No 300/2008
Civil aviation security regulation amended to integrate AI Act requirements for AI systems used in aviation screening
General
Art.
103
Article 103 - Amendment to Regulation (EU) No 167/2013
Agricultural and forestry vehicle regulation amended to integrate AI Act requirements for AI systems in machinery
General
Art.
104
Article 104 - Amendment to Regulation (EU) No 168/2013
Two- and three-wheel vehicle regulation amended to integrate AI Act requirements for AI systems in motorcycles and mopeds
General
Art.
105
Article 105 - Amendment to Directive 2014/90/EU
Marine equipment directive amended to integrate AI Act requirements for AI systems in shipboard safety equipment
General
Art.
106
Article 106 - Amendment to Directive (EU) 2016/797
Rail interoperability directive amended to integrate AI Act requirements for AI systems in railway operations
General
Art.
107
Article 107 - Amendment to Regulation (EU) 2018/858
Motor vehicle type-approval regulation amended to integrate AI Act requirements for AI systems in cars, vans and trucks
General
Art.
108
Article 108 - Amendments to Regulation (EU) 2018/1139
EU aviation safety regulation amended to integrate AI Act requirements for aircraft, drones and air traffic management AI systems
General
Art.
109
Article 109 - Amendment to Regulation (EU) 2019/2144
Motor vehicle general safety regulation amended to integrate AI Act requirements for AI-powered ADAS and safety systems
General
Art.
110
Article 110 - Amendment to Directive (EU) 2020/1828
Consumer organisations can bring collective redress actions for AI Act violations harming consumers' collective interests
General
Art.
111
Article 111 - AI Systems Already Placed on the Market or Put into Service
AI systems already deployed before the Act's application dates benefit from transitional protection — with important exceptions
General
Art.
112
Article 112 - Evaluation and Review
The Commission must evaluate the Act's effectiveness every four years — with a dedicated 2028 review of its impact on SMEs
General
Art.
113
Article 113 - Entry into Force and Application
Updated by the Digital Omnibus: prohibited practices Feb 2025, GPAI Aug 2025, Annex III high-risk Dec 2027, Annex I Aug 2028
General