Printed from Production AI Institute public record

https://www.productionai.institute/insights/eu-ai-act-production-ai

Production AI Institute · Public recordRecord
Production AI Institute
Briefing
Briefing

Today's public AI briefing: what changed, what went wrong, and what the evidence says.

Open Briefing →
Today's AI briefingThe daily record of what changed and broke.Public record explorerSearch every incident, entity, and source.
Check
Check

Inspect tools, incidents, and data-use disclosures against the public record.

Open Check →
Check an AI toolWhat a tool actually does with your data.Run exposure checkTest your own stack against the record.Data-use indexDisclosures across the major AI tools.Incident registryDocumented production AI failures.
The Lab
The Lab

Independent research instruments: model and agent scorecards, moral-reasoning evals, and ecosystem assessments.

Open The Lab →
The LabHow frontier models and agents actually perform.AI Morality CompassTest models on hard moral cases.Agent readinessIs the agent ecosystem production-ready?Ecosystem assessmentsIndependent reviews of the AI stack.Model & agent evalsOpen evaluations and their results.Research libraryEvidence-led analysis and briefings.
Learn
Learn

The open standard, the tools built on it, and the research that interprets the record.

Open Learn →
The FrameworkThe open production safety framework, explained.AI Adoption GuideFive stages from gated access to safe autonomy.Production AI Deployment GuideBuild a governed production system on Microsoft or AWS.Five-Year Automation RoadmapSequence enterprise capability, controls, and value.WorkflowOS · open sourceBuild governed AI workflows.Workflow libraryReady-made governed workflows.InsightsResearch articles on the record.
Act
Act

Turn uncertainty into public evidence: ask, disclose, build evidence, or correct.

Open Act →
Ask for disclosureRequest a public data-use answer.Submit a correctionFlag something wrong or missing on the record.Save a watchTell PAI what to keep current for you.
Method
Method

How the public record is made, governed, corrected, cited, and kept independent.

Open Method →
How records are madeSourcing, review, and correction.
Check an AI tool
Record
Record
Check an AI tool
Production AI public record - EditorialMethod →
RegulatoryEU AI Act · In Force August 2024

What the EU AI Act Means for
Your Production AI System

The world's first comprehensive AI legal framework. In force August 2024, with obligations applying progressively through 2026–2027. If you deploy AI in or to the EU, this applies to you — regardless of where you are based.

Legal note: Reflects the EU AI Act as published August 2024. Guidance updates and implementing acts may have changed requirements. Verify with qualified legal counsel. PAI Reference Article v1.0 · CC BY 4.0.

Scope: Does the Act Apply to You?

The EU AI Act applies to providers (organisations that develop or place AI systems on the market), deployers (organisations that use AI systems in a professional context), importers, and distributors. Geographic scope follows the effect of the AI system, not the location of the developer.

You are in scope if any of the following apply:

  • You place an AI system on the EU market (including software-as-a-service accessible from the EU)
  • The output of your AI system is used within the EU
  • You are located in the EU and deploy an AI system, regardless of where the system is hosted
  • You use a third-party AI system (including cloud AI APIs) in a business context involving EU users or data

Common misconception: Many non-EU organisations assume the Act does not apply to them. The jurisdictional reach is designed to be broad. If your system affects people in the EU, legal advice on applicability is warranted before assuming you are out of scope.

The Four Risk Tiers

The Act classifies AI systems into four risk tiers. Your obligations depend entirely on which tier your system falls into.

Unacceptable Risk

Prohibited

AI systems that pose unacceptable risks to fundamental rights are prohibited entirely. This includes social scoring by public authorities, real-time biometric surveillance in public spaces (with narrow exceptions), manipulation of persons using subliminal techniques, and exploitation of vulnerabilities of specific groups.

Your obligation: Do not deploy. These use cases are banned.

High Risk

Regulated

Systems used in critical infrastructure, education, employment, essential services, law enforcement, migration, and administration of justice. Also applies to safety components of products covered by existing EU product safety legislation.

Your obligation: Full compliance regime: conformity assessment, technical documentation, risk management system, human oversight measures, accuracy and robustness requirements, registration in the EU AI Act database.

Limited Risk

Transparency Obligations

AI systems that interact directly with users (chatbots, emotion recognition, AI-generated content). Users must be informed they are interacting with an AI. Deepfakes must be disclosed as AI-generated.

Your obligation: Transparency disclosures. Users must know they are engaging with AI. No conformity assessment required.

Minimal Risk

Voluntary Measures

The vast majority of AI applications fall here: spam filters, AI in video games, recommendation engines, most productivity tools. The Act does not impose mandatory requirements but encourages voluntary codes of practice.

Your obligation: No mandatory obligations. Voluntary adherence to codes of practice is encouraged.

High-Risk System Obligations in Detail

If your system is classified as high-risk, the Act imposes a significant ongoing compliance regime. This is not a point-in-time certification — it is continuous obligation.

Risk Management System

Establish, implement, document, and maintain a risk management system throughout the AI system's lifecycle. Identify and analyse known and foreseeable risks. Evaluate risks arising from post-market monitoring. Implement risk mitigation measures.

Technical Documentation

Prepare and maintain comprehensive technical documentation before market placement. Includes a general description, design specifications, development data, training and testing methodology, accuracy metrics, and cybersecurity measures. Must be available to national authorities on request.

Data Governance

Training, validation, and testing data must meet quality criteria for relevance, representativeness, freedom from errors, and completeness. Document data collection methodologies, data provenance, and any known limitations.

Logging and Traceability

High-risk AI systems must have logging capabilities that enable traceability of operation throughout the system's lifetime. Logs must be stored for at minimum the system's operating lifetime or 10 years, whichever is longer.

Transparency and User Information

Provide deployers with instructions for use covering system capabilities and limitations, accuracy and robustness characteristics, human oversight requirements, and how to interpret outputs correctly.

Human Oversight

High-risk AI systems must be designed to allow human oversight during operation. Specific requirements: individuals must be able to understand system capabilities and limitations, detect anomalies, and override or interrupt operation. This cannot be a nominal compliance checkbox — oversight must be genuinely implementable.

Accuracy, Robustness, and Cybersecurity

Systems must achieve appropriate levels of accuracy, robustness, and cybersecurity. For systems making consequential decisions, accuracy must be declared and validated. Resilience against attempts to alter the system or its output must be built in.

Conformity Assessment

Before market placement, conduct conformity assessment. For most high-risk AI systems, this can be a self-assessment against Annex VI requirements with supporting documentation. For certain systems (biometrics, critical infrastructure), third-party assessment by a notified body is required.

Implementation Timeline

The Act implements obligations progressively. The timeline as of the August 2024 entry into force:

August 2024Entry into force

Act published in Official Journal. 24-month implementation period begins for most provisions.

February 2025Prohibited practices

Chapter II (unacceptable risk) prohibitions apply. Immediately ban any systems falling into this category.

August 2025GPAI obligations

General Purpose AI (GPAI) model obligations apply. Affects providers of foundation models placed on the EU market.

August 2026High-risk obligations

Article 6(2) high-risk AI system obligations fully apply. The majority of compliance work must be complete by this date.

August 2027Existing systems

High-risk AI systems already in use before August 2026 must comply by this date (3-year grace period).

Practical Compliance Starting Points

For organisations beginning compliance work now, the following sequence reflects the most common practical starting point:

  1. AI system inventory: Document every AI system in use or development, including third-party AI APIs integrated into products. You cannot classify what you have not inventoried.
  2. Risk classification: For each system, determine risk tier using the Act's Annex III (high-risk use cases) and Article 5 (prohibited practices). Obtain qualified legal review for any borderline classifications.
  3. High-risk gap assessment: For confirmed high-risk systems, conduct a gap assessment against the eight Article 9–15 requirements. Prioritise logging/traceability and human oversight — these typically require the most lead time.
  4. Technical documentation: Begin creating and maintaining technical documentation now. This is not a one-time project — it must be a living document updated with every material change.
  5. Governance structures: Assign an AI Act compliance owner. Define internal escalation paths for classification decisions and incident response. The Act imposes obligations on organisations, not just on technical systems.
  6. Supplier review: If you use third-party AI (including commercial AI APIs), review supplier contracts for EU AI Act provisions. Providers of GPAI models have their own obligations, but deployers carry downstream responsibility for deployment context.

This is not legal advice. The EU AI Act is complex legislation with implementing acts, delegated regulations, and national transposition that continue to evolve. This article provides a practical overview for technical and operational teams. Classification decisions and compliance strategies for high-risk systems require qualified EU legal counsel.

Related Resources

AI Behaviour ContractsHuman-in-the-Loop DesignCPAA CertificationCAIG Certification (Governance)
Public record

This record is maintained by PAI and free to cite. If something is wrong or missing, tell us. Corrections and source suggestions keep the record honest.

Follow policy changes ->Save a watch ->Submit a correction
Records are free to cite. citation guidance.
PAI
Production AI Institute

The public record and operating memory for production AI: what changed, what broke, and what the evidence says.

WorkflowOS · open source (MIT)
Navigate
Briefing
OverviewToday's AI briefingPublic record explorer
Check
Check an AI toolRun exposure checkData-use indexIncident registry
The Lab
The LabAI Morality CompassAgent readinessEcosystem assessmentsModel & agent evalsResearch library
Learn
The FrameworkAI Adoption GuideProduction AI Deployment GuideFive-Year Automation RoadmapWorkflowOS · open sourceWorkflow libraryInsights
Act
Ask for disclosureSubmit a correctionSave a watch
Method & trust
How records are madeCorrectionsHow to citeContact
© 2026 Production AI Institute · CC BY 4.0
AboutPrivacyTermsSecurityGovernanceIndependence