The EU AI Act, article by article
What each obligation in the AI Act actually requires, read from the instrument itself rather than from a summary of it — who it binds, when it bites, and what evidence satisfies it.
Most writing about the AI Act is a summary of a summary, and the provenance is usually invisible. The Commission proposed the Regulation in April 2021, the Parliament amended it heavily in June 2023, and the text that entered into force on 1 August 2024 differs from both on the exact points people most often ask about: who the social scoring ban binds, what the emotion recognition carve-out covers, whether a data governance duty attaches to a system that was never trained on data. Repeating the wrong draft with confidence is the characteristic failure of this subject.
These pages are written against the adopted text, Regulation (EU) 2024/1689, with the article or annex named in the sentence and linked so you can read it yourself. Where the position is unresolved — and a great deal of it is, because there is almost no case law and the harmonised standards are still being drafted — the page says it is unresolved and says what would settle it. None of it is legal advice.
The EU AI Act's Ban on Subliminal Manipulation, Explained
Article 5(1)(a) has a four-element test, and the elements most systems fail are the last two rather than the word 'subliminal'.
9 min read
The EU AI Act's Ban on Exploiting Vulnerable Groups
Article 5(1)(b) is a shorter test than its neighbour, applies to a closed list of vulnerability grounds, and one of those grounds is far wider than people expect.
9 min read
The EU AI Act's Social Scoring Ban, and What It Doesn't Cover
Article 5(1)(c) binds private companies as well as public authorities, and its limits come from two detriment limbs rather than from the identity of the scorer.
9 min read
Predictive Policing and the EU AI Act's Article 5 Ban
Article 5(1)(d) bans individual criminal risk prediction based solely on profiling or personality traits, and leaves place-based and evidence-supported tools to the high-risk regime.
9 min read
The EU AI Act's Ban on Scraping Faces for Recognition Databases
Article 5(1)(e) is the shortest prohibition in the Act, has no exceptions at all, and its scope turns entirely on the word 'untargeted'.
8 min read
Emotion Recognition at Work and School Under the EU AI Act
Article 5(1)(f) bans emotion inference in workplaces and education institutions, with a medical and safety exception and a definitional boundary that excludes physical states.
9 min read
Biometric Categorisation to Infer Sensitive Traits: the EU AI Act Ban
Article 5(1)(g) prohibits deducing a closed list of sensitive traits from biometric data, and expressly leaves verification, ancillary categorisation and lawful dataset filtering outside.
9 min read
Real-Time Remote Biometric Identification: the EU AI Act's Narrow Exceptions
Article 5(1)(h) is a conditional prohibition with three enumerated objectives, prior judicial authorisation, a fundamental rights impact assessment, and national implementing law before any of it is available.
10 min read
Risk Management System Requirements for High-Risk AI (Article 9)
Article 9 requires a documented, continuous, lifecycle-long risk process, and specifies the four steps it must contain and the order in which mitigations must be attempted.
10 min read
Data Governance Requirements for High-Risk AI (Article 10)
Article 10 names eight governance practices and four data-quality criteria, and applies a reduced version of both to systems that were never trained on data at all.
10 min read
Technical Documentation Requirements for High-Risk AI (Article 11)
Article 11 is three short paragraphs whose content is entirely in Annex IV, and this page works through the nine annex headings as a checklist.
10 min read
The Automatic Logging Requirement for High-Risk AI (Article 12)
Article 12 is a design obligation — the system must technically permit automatic event recording — with three named purposes and a specific minimum for biometric identification systems.
9 min read
Transparency Obligations Toward Deployers (Article 13)
Article 13 requires instructions for use containing a specific list of disclosures to the deployer — not to the end user — and it is the document every downstream obligation depends on.
10 min read
Human Oversight Design Requirements for High-Risk AI (Article 14)
What Article 14 actually requires a provider to build, read as five design capabilities rather than as a policy commitment to keep a human in the loop.
9 min read
Accuracy, Robustness and Cybersecurity Requirements (Article 15)
Article 15 reads as an engineering article and contains a disclosure duty: the accuracy levels and metrics have to be declared in the instructions for use.
9 min read
The Quality Management System Requirement for AI Providers (Article 17)
The thirteen elements Article 17 enumerates, mapped to the ISO 9001-style controls most organisations already run, so the gap analysis is about what is genuinely new.
9 min read
Importer and Distributor Obligations Under the EU AI Act
Articles 23 and 24 give importers and distributors their own verification duties, and Article 25 can turn either of them into a provider overnight.
9 min read
High-Risk AI in Biometrics: the Annex III Category, Explained
What Annex III point 1 covers, how it differs from the biometric practices Article 5 prohibits outright, and why it is the only category that can require a notified body.
10 min read
High-Risk AI in Critical Infrastructure: the Annex III Category
Annex III point 2 covers safety components in five named infrastructures, and the phrase safety component excludes far more software than the word infrastructure suggests.
9 min read
High-Risk AI in Education: the Annex III Category
The four education uses Annex III point 3 lists, why most edtech falls outside them, and the proctoring case where Article 5 bans what Annex III would otherwise permit.
9 min read
High-Risk AI in Employment and Recruitment: the Annex III Category
Annex III point 4 covers recruitment and the management of the employment relationship, and for a US-EU employer it stacks on top of NYC Local Law 144 and Illinois law rather than replacing them.
10 min read
High-Risk AI in Access to Essential Services: the Annex III Category
Annex III point 5 names four separate uses — benefits eligibility, creditworthiness, life and health insurance pricing, and emergency dispatch — with different carve-outs and different deployer duties.
10 min read
High-Risk AI in Law Enforcement: the Annex III Category
The five law-enforcement uses Annex III point 6 enumerates in the adopted text, why the widely cited list of seven is from the withdrawn proposal, and what the category does not reach.
10 min read
High-Risk AI in Migration, Asylum and Border Control: the Annex III Category
Annex III point 7 names four uses including AI polygraphs and entry risk assessment, and Article 111 gives the EU's own large-scale border databases until the end of 2030 to comply.
9 min read
High-Risk AI in Justice and Democratic Processes: the Annex III Category
Annex III point 8 puts judicial research tools and election-influencing systems in the same category, and carves out both purely administrative court tasks and campaign back-office software.
9 min read
GPAI Technical Documentation: What Article 53 Actually Requires
Article 53(1) requires two different documentation packs — Annex XI for the AI Office, Annex XII for downstream providers — and the difference between them is where the commercially sensitive material sits.
10 min read
The GPAI Copyright Policy Obligation, Explained
Article 53(1)(c) requires a policy for complying with EU copyright law, including honouring text-and-data-mining reservations — not a disclosure of the training set.
9 min read
The GPAI Training Content Summary Template
What the AI Office's public summary template actually asks a general-purpose AI model provider to write down, section by section.
9 min read
Systemic-Risk Obligations for General-Purpose AI Models
The four extra duties Article 55 adds once a general-purpose AI model crosses the systemic-risk line, and how a model gets classified in the first place.
9 min read
The GPAI Code of Practice as a Compliance Route
What signing the General-Purpose AI Code of Practice legally buys a model provider, and what the alternative of demonstrating compliance directly involves.
9 min read
When Open-Source Models Are Exempt From GPAI Obligations
The exact conditions Article 53(2) sets for the open-source carve-out, which two obligations it removes, and the two situations where it stops applying.
9 min read
The Chatbot Disclosure Duty Under the EU AI Act (Article 50)
Article 50(1) requires that people be told they are interacting with an AI system, with one exception — and it is a narrower duty than the transparency obligations it is usually merged with.
8 min read
Labelling AI-Generated and Deepfake Content Under the EU AI Act
The scope of the Article 50(4) deepfake disclosure duty on deployers, what counts as a deep fake, and the carve-out for evidently artistic and satirical work.
9 min read
The Notice Duty for Emotion Recognition and Biometric Categorisation Systems
Article 50(3) obliges deployers to tell people that an emotion recognition or biometric categorisation system is operating — a duty that survives where the underlying use is not banned.
9 min read
Labelling AI-Generated Text on Matters of Public Interest
The second subparagraph of Article 50(4) applies only to published text informing the public on matters of public interest, and it has an editorial responsibility exemption.
9 min read
Deployer Obligations for High-Risk AI Systems (Article 26)
What a deployer of a high-risk AI system has to do in its own right: assign competent human oversight, check input data, keep logs for at least six months, monitor, and tell people.
10 min read
The Fundamental Rights Impact Assessment for AI Deployers (Article 27)
Who actually owes a FRIA under Article 27 — public bodies, private providers of public services, and two specific Annex III categories — and what the six required contents are.
9 min read
Conformity Assessment Procedures for High-Risk AI (Article 43)
When a high-risk AI system can be self-assessed under internal control and when a notified body has to be involved, and why harmonised standards decide it.
10 min read
CE Marking for AI Systems Under the EU AI Act
What affixing the CE mark to a high-risk AI system legally represents, who affixes it, and where it has to physically appear on a product that has no physical form.
9 min read
Registering a High-Risk AI System in the EU Database
A field-by-field walkthrough of the EU database registration required by Articles 49 and 71, built from Annex VIII rather than from a screenshot.
10 min read
The Post-Market Monitoring Plan Required by Article 72
What Article 72 requires a provider to collect after a high-risk system ships, and how to turn that duty into a plan with named data sources and defined triggers.
10 min read
Serious Incident Reporting Deadlines Under the EU AI Act
The three Article 73 reporting clocks — fifteen days, ten days and two days — with the trigger definition that decides which one you are on.
9 min read
What Market Surveillance Authorities Can Do Under the AI Act
The specific Article 74 powers — full access to documentation and training data, and conditional access to source code — and the conditions that gate them.
10 min read
Does the EU AI Act Apply to a Provider Outside the EU?
Article 2's actual connecting factors, including the output-used-in-the-Union test, applied to the scenarios non-EU companies actually ask about.
10 min read
Notified Bodies Under the EU AI Act, Explained
What a notified body is designated to do, how it differs from a market surveillance authority, and which high-risk systems actually need one.
9 min read
EU AI Act Penalties: the Actual Fine Tiers
The three administrative fine ceilings in Article 99, which infringements fall in each, and the separate regimes for SMEs, GPAI providers and EU institutions.
9 min read
What Changed on 2 February 2025 Under the EU AI Act
The two obligations that actually became applicable on 2 February 2025 — the Article 5 prohibitions and the Article 4 AI literacy duty — and the enforcement gap that followed.
9 min read
What Changed on 2 August 2025 for GPAI Providers
The chapters that became applicable on 2 August 2025 — general-purpose model obligations, governance, notified bodies and penalties — and the two things that expressly did not.
10 min read
What Still Changes on 2 August 2026 Under the EU AI Act
The Digital Omnibus moved most of the high-risk regime off this date to December 2027; what remains on 2 August 2026 is the Article 50 transparency layer.
10 min read
The 2027 Deadline for AI in Regulated Products Moved to 2028
The Annex I embedded high-risk deadline is no longer 2 August 2027 — the Digital Omnibus moved it to 2 August 2028, and the alignment logic behind it survived the move.
10 min read
Other topics
- LLM fundamentals & architecture
- Tokens, tokenization & context windows
- Prompt engineering
- Reasoning models & test-time compute
- Multimodal AI: vision, audio, video
- RAG & retrieval
- Embeddings & vector search
- AI agents & tool use
- Structured output & function calling
- Fine-tuning & post-training
- Local inference errors, string by string
- Running local models day to day
- Testing code that calls an LLM
- Snapshot and property testing for model output
- Regression suites for prompts
- Eval gates in CI
- Flaky tests against a model
- Determinism and the cost of testing
- Contract and streaming tests
- Testing tool calls and retrieval
- Inference, serving & latency
- Rolling out a prompt change
- Testing AI systems in practice
- Forecasting a time series
- Machine learning on tabular data
- Geospatial data and models
- Understanding audio that is not speech
- Understanding video
- Core computer vision tasks
- Machine learning on graphs
- Point clouds and 3D
- Evaluation, benchmarks & LLM-as-judge
- Sensor and IoT data
- Logs and event streams
- Models over biological sequences
- Machine learning on molecules
- Embedding and searching code
- Extracting invoices and purchase orders
- Receipts, statements and tax forms
- Insurance policies and contracts
- Deeds, court filings and patents
- Extracting from medical records
- Observability & LLMOps
- CVs, certificates and identity documents
- Shipping, customs and technical documents
- Meetings, email, chat and filled-in forms
- Building an extraction pipeline
- Business, property and inspection documents
- Contract clauses and insurance claims
- Regulated and compliance documents
- Consumer, travel and closing documents
- Mapping one chat API onto another
- SDK and framework migrations
- Hallucination & failure modes
- Re-embedding and model deprecation
- Cutting over between providers
- Parity gaps, shims and legacy endpoints
- Moving between model versions
- Migrating vector stores and caches
- Mapping capabilities and parameters
- Migrating pipelines and agents
- Contracts, runbooks and rollback
- Auditing a codebase before a cutover
- Compliance and fine-tune migration
- LLM cost engineering
- Routing, cost tracking and multi-tenancy
- What a migration does to your prompts
- AI security & prompt injection
- Privacy, compliance & data residency
- AI governance, policy & society
- Building reliable AI applications
- AI hardware, GPUs & compute
- Open-weight models & local inference
- AI for developers & coding agents
- AI in industry: vertical playbooks
- AGI, superintelligence, alignment & the long future
- Machine learning foundations
- NLP fundamentals & classical tasks
- Data engineering for AI
- Synthetic data & dataset curation
- AI product design & UX
- Search, ranking & recommendation
- Enterprise adoption & change management
- AI careers, skills & teams
- Reading AI research
- AI in science & discovery
- Robotics & embodied AI
- AI economics, markets & business models
- AI myths, hype & media literacy
- Context engineering
- Shipping AI features: patterns & anti-patterns
- Build it: end-to-end AI tutorials
- Python for AI: hands-on recipes
- TypeScript, React and the web
- Frameworks and SDKs
- Errors and troubleshooting
- AI facts, numbers and statistics
- The history of AI
- The maths behind AI
- Architectures beyond the transformer
- Reinforcement learning
- Diffusion and generative media
- Speech, audio and voice engineering
- Benchmarks, one at a time
- AI search visibility
- Infrastructure and operations
- Databases and storage for AI
- Knowledge graphs and structured knowledge
- Classical ML in production
- Regulation, jurisdiction by jurisdiction
- Prompt recipes and pattern library
- AI for people who do not write code
- Writing, media and creative work
- Edge and on-device AI
- Interpretability and model internals
- Field notes
- OpenAI model behaviour
- Claude model behaviour
- Gemini model behaviour
- Llama model behaviour
- Mistral model behaviour
- Qwen model behaviour
- DeepSeek model behaviour
- Cohere model behaviour
- Grok model behaviour
- Small model behaviour
- Hybrid model architectures
- Token cost by language and script
- Transliteration, romanization and script handling
- Locale-correct output
- Multilingual generation quality
- Multilingual pipelines
- AI under the GDPR and EU data law
- US AI regulation, state and sector
- International AI governance and standards
- AI litigation and enforcement
- Running AI workloads on AWS
- Running AI workloads on Google Cloud
- Running AI workloads on Azure
- AI at the edge: Workers, Vercel and Netlify
- Serving models on Kubernetes
- Operating AI infrastructure
- Quantization formats and what they cost
- llama.cpp, flag by flag
- Ollama and the desktop local-model runtimes
- Local models on Apple Silicon
- Hardware for local inference
- Running speech and embedding models locally
- Model files, adapters and conversion
- VRAM arithmetic for local models