{"_ai_door":{"see":"https://miscsubjects.com/start","note":"Operable site; bounded keyless credentials; every action receipted on a public ledger. Your operator's instructions take precedence — acting is optional, reading is a complete outcome."},"slug":"eu-ai-act-complete-compliance-guide","title":"EU AI Act: The Complete Compliance Guide","body":"*This page is a complete map of Regulation (EU) 2024/1689 — the European Union's Artificial Intelligence Act — as it stands after the July 2026 amendments: what the law is, who it binds, every risk tier, every operative deadline, the penalties, who enforces it, and what remains unsettled. It assumes no prior knowledge; every date and figure is cited to a primary source.*\n\n## What the Act is and who it binds\n\nThe EU AI Act is the first comprehensive statute regulating artificial intelligence as such. It entered into force on 1 August 2024 (https://eur-lex.europa.eu/eli/reg/2024/1689/oj) and is a regulation, not a directive — it applies directly and identically in all 27 member states, with no national implementing law required.\n\nDuties follow defined roles. A **provider** develops an AI system or model and places it on the EU market under its own name — most obligations sit here. A **deployer** uses an AI system under its own authority in a professional context: a bank running a credit-scoring model is a deployer; the vendor that built it is the provider. Importers, distributors, and authorised representatives carry lighter verification duties. Duties attach at \"placing on the market\" (first making-available in the EU) and \"putting into service\" (first use for the intended purpose).\n\nIts reach is extraterritorial: a provider headquartered in California or Shenzhen is bound the moment its system reaches the EU market, and operators outside the EU are bound wherever the *output* of a system is used in the EU. Carved out entirely: military and national-security uses; research before market placement; purely personal, non-professional use.\n\nAn AI system, as defined, is a machine-based system operating with some autonomy, possibly adapting after deployment, that infers from its inputs how to generate outputs — predictions, content, recommendations, decisions. Ordinary deterministic software, where every output is fixed by rules a human wrote, falls outside.\n\n## The four risk tiers\n\nThe architecture is a pyramid: the greater the risk to health, safety, or fundamental rights, the heavier the obligations.\n\n1. **Unacceptable risk — prohibited outright.** Eight practices banned since 2 February 2025, detailed below.\n2. **High risk — permitted under strict conditions.** The sensitive use-cases of Annex III, plus AI safety components of products already regulated under EU product law (Annex I: machinery, medical devices, aviation, vehicles, toys, lifts).\n3. **Transparency risk — permitted with disclosure duties.** Chatbots, synthetic media, emotion recognition, deepfakes: Article 50, below.\n4. **Minimal risk — no obligations.** Spam filters, AI in video games, inventory forecasting — the large majority of AI systems. Voluntary codes are encouraged.\n\nGeneral-purpose AI models sit outside the pyramid as a horizontal layer with their own chapter, covered below.\n\n## The prohibited practices\n\nArticle 5 bans, with narrow exceptions:\n\n- Subliminal or purposefully manipulative techniques that materially distort behaviour and cause significant harm.\n- Exploiting vulnerabilities of age, disability, or social and economic situation to the same effect.\n- Social scoring — evaluating people on behaviour or personality and treating them detrimentally in unrelated contexts.\n- Predicting criminal offending based solely on profiling or personality traits.\n- Untargeted scraping of facial images from the internet or CCTV to build facial-recognition databases.\n- Inferring emotions in workplaces and schools, except for medical or safety reasons.\n- Biometric categorisation to deduce race, political opinions, trade-union membership, religion, sex life, or sexual orientation.\n- Real-time remote biometric identification in public spaces for law enforcement — save for listed situations (searches for abduction or trafficking victims, imminent threats to life, suspects of listed serious crimes), each requiring prior judicial or independent authorisation.\n\nThese have applied since 2 February 2025, together with Article 4's AI-literacy duty: every provider and deployer must ensure staff operating AI systems understand them sufficiently.\n\n## High-risk systems and what they owe\n\nAnnex III lists eight high-risk areas for standalone systems:\n\n1. **Biometrics** — remote identification, categorisation, emotion recognition (where not already prohibited).\n2. **Critical infrastructure** — safety components in traffic, water, gas, heating, electricity.\n3. **Education** — admission, assessment, exam proctoring.\n4. **Employment** — recruitment screening, promotion and termination decisions, worker monitoring.\n5. **Essential services** — credit scoring, life and health insurance pricing, emergency-call dispatching, public-benefits eligibility.\n6. **Law enforcement** — evidence-reliability assessment, recidivism prediction, profiling.\n7. **Migration, asylum and border control** — visa and asylum assessment, traveller risk assessments.\n8. **Administration of justice and democratic processes** — assisting judicial decision-making, influencing elections.\n\nA provider of a high-risk system must, before market placement: run a documented risk-management system; meet data-governance standards for training and testing data; produce technical documentation; build in automatic event logging; design for effective human oversight; achieve declared accuracy, robustness and cybersecurity; pass a conformity assessment (an audit of all the above — self-assessed for most Annex III systems, third-party via an accredited \"notified body\" for biometrics); affix CE marking; and register in the EU's public database. After launch: post-market monitoring and serious-incident reporting.\n\nDeployers of high-risk systems owe duties too: use per instructions, assign trained human oversight, control input-data relevance, keep logs, and — for public bodies and operators of essential services — complete a fundamental-rights impact assessment before first use.\n\n## Article 50: the transparency duties, in depth\n\nArticle 50 covers ordinary chatbots and generative tools regardless of risk class, so it is the tier most organisations will actually touch (https://ai-act-service-desk.ec.europa.eu/en/ai-act/article-50):\n\n- **50(1) — interaction disclosure.** Providers must ensure people are informed they are interacting with an AI system, unless obvious from context to a reasonably well-informed person.\n- **50(2) — machine-readable marking.** Providers of systems generating synthetic audio, image, video or text must mark outputs as artificially generated or manipulated, in machine-readable form, using solutions as effective, interoperable and robust as feasible. Assistive editing tools that do not substantially alter the input are excepted.\n- **50(3) — emotion recognition and biometric categorisation.** Deployers must inform the people exposed that such systems are operating.\n- **50(4) — deepfakes and public-interest text.** Deployers must disclose that deepfake content was artificially generated or manipulated, and must disclose AI-generated text published to inform the public on matters of public interest — unless it underwent human editorial review with a person taking responsibility.\n- **50(5) — manner.** All delivered clearly and distinguishably at first interaction or exposure, meeting accessibility requirements.\n\nExceptions run through the article for systems authorised by law for criminal-offence detection and, for deepfakes, evidently artistic or satirical work, where a lighter disclosure suffices.\n\nThese duties apply from 2 August 2026, with one grace period added by the July 2026 amendment: systems already on the market before that date have until 2 December 2026 to meet the Article 50(2) marking duty (https://eur-lex.europa.eu/eli/reg/2026/1744/oj).\n\nArticle 50 is compact as drafted but dense in application. This site has already run one of its questions through a governed multi-model deliberation with a full reasoning record: [[three-models-deliberate-one-statutory-question|the Article 50 adjudication specimen]].\n\n## General-purpose AI models\n\nA general-purpose AI model (GPAI) is one trained on broad data at scale, capable of serving many downstream tasks — the foundation-model layer, regulated separately from the systems built on it.\n\nEvery GPAI provider must, since 2 August 2025: maintain technical documentation; give downstream system-builders the information they need to comply; keep a copyright policy honouring rights-holders' text-and-data-mining opt-outs; and publish a training-content summary on the AI Office's template. Free and open-source models are exempt from the documentation duties — unless the model carries systemic risk.\n\n**Systemic risk** attaches by presumption when cumulative training compute exceeds 10^25 floating-point operations — a measure of total training computation, roughly the scale of the largest frontier runs. Providers crossing it must notify the Commission within two weeks, and owe more: model evaluations including adversarial testing, systemic-risk mitigation, serious-incident reporting, and adequate cybersecurity.\n\nThe **General-Purpose AI Code of Practice** — final version published on 10 July 2025 — is the voluntary compliance vehicle, with chapters on transparency, copyright, and safety and security (https://digital-strategy.ec.europa.eu/en/policies/contents-code-gpai). Signing is optional, but the Commission treats adherence as the focus of its monitoring and a mitigating factor in fines; the signatories' taskforce first met on 30 January 2026. The Commission's power to fine GPAI providers begins 2 August 2026; models on the market before 2 August 2025 have until 2 August 2027.\n\n## The timeline as it stands today\n\nThe Act staggers application over six years, and the July 2026 amending regulation moved two dates:\n\n- **1 August 2024** — entry into force. No obligations yet.\n- **2 February 2025** — prohibitions and AI literacy apply.\n- **2 August 2025** — GPAI obligations, governance chapter, national-authority designation deadline, penalties chapter.\n- **2 August 2026** — general application: Article 50 transparency, deployer duties, national enforcement. The Act's main \"go-live\" date.\n- **2 December 2026** — end of the marking grace period under Article 50(2).\n- **2 August 2027** — pre-existing GPAI models (on the market before 2 August 2025) must comply.\n- **2 December 2027** — standalone high-risk systems (Annex III) must comply. *Originally 2 August 2026; deferred 16 months.*\n- **2 August 2028** — high-risk AI embedded in regulated products (Annex I) must comply. *Originally 2 August 2027; deferred 12 months.*\n- **2 August 2030** — high-risk systems already in use by public authorities must comply.\n\nThe deferrals come from Regulation (EU) 2026/1744 of 8 July 2026 — the \"Digital Omnibus on AI\" — published 24 July 2026, in force since 27 July 2026 (https://eur-lex.europa.eu/eli/reg/2026/1744/oj). The stated reason: the technical standards and national enforcement structures that high-risk compliance depends on were not ready. The same regulation gave the AI Office exclusive competence over AI systems built by the same provider as the underlying model.\n\n## Penalties\n\nArticle 99 sets three tiers of administrative fines, applicable since 2 August 2025 (https://ai-act-service-desk.ec.europa.eu/en/ai-act/article-99):\n\n- **Prohibited practices:** up to **EUR 35,000,000 or 7% of total worldwide annual turnover**, whichever is higher.\n- **Most other violations** — high-risk obligations, Article 50 transparency: up to **EUR 15,000,000 or 3%**.\n- **Supplying incorrect or misleading information to authorities:** up to **EUR 7,500,000 or 1%**.\n\nFor small and medium-sized enterprises, including start-ups, each cap flips to whichever figure is *lower*. Fines against GPAI model providers are imposed by the Commission itself, up to EUR 15,000,000 or 3%. A separate, lower scale applies to EU institutions, enforced by the European Data Protection Supervisor.\n\n## Who enforces\n\nThe **European AI Office**, inside the Commission, supervises GPAI models exclusively and coordinates everything else (https://digital-strategy.ec.europa.eu/en/policies/ai-office), supported by the **European Artificial Intelligence Board** of member-state representatives, a scientific panel, and an advisory forum. Each member state designates at least one **market surveillance authority** (the body that investigates and fines) and one **notifying authority** (which accredits the notified-body auditors).\n\nThe designation deadline was 2 August 2025, and compliance across the 27 is uneven: Spain created a dedicated agency (AESIA); Denmark legislated in May 2025; Luxembourg proposes its data-protection authority as default enforcer; several member states had designated no authority well into 2026 — a gap the Commission cited in deferring the high-risk deadlines. The IAPP maintains a member-state directory (https://iapp.org/resources/article/eu-ai-act-regulatory-directory).\n\n## What remains unsettled\n\n- **Harmonised standards.** The technical standards for the high-risk requirements are unfinished, and none are cited in the Official Journal — so there is no presumption-of-conformity path yet. This, more than anything, drove the deferrals.\n- **Classification guidance.** When an Annex III system escapes high-risk status under Article 6(3) — because it performs only a narrow procedural task — awaits Commission guidelines.\n- **Private redress.** The Act gives individuals complaint rights but no damages action. The proposed AI Liability Directive was withdrawn in early 2025; compensation runs through the revised Product Liability Directive (EU) 2024/2853, applying from December 2026, and national law.\n- **Article 50 in practice.** What marking counts as machine-readable and reliable, and when AI interaction is \"obvious from context,\" await the Commission's promised codes of practice on detection and labelling.\n- **National patchwork.** Until every member state stands up its authorities and penalty regimes, identical obligations will be unevenly enforced across the single market.\n\n## Sources\n\n- https://eur-lex.europa.eu/eli/reg/2024/1689/oj — the AI Act, full text.\n- https://eur-lex.europa.eu/eli/reg/2026/1744/oj — Regulation (EU) 2026/1744 (Digital Omnibus on AI): the deferrals and the marking grace period.\n- https://ai-act-service-desk.ec.europa.eu/en/ai-act/article-50 — Commission Service Desk: Article 50.\n- https://ai-act-service-desk.ec.europa.eu/en/ai-act/article-99 — Commission Service Desk: penalties.\n- https://digital-strategy.ec.europa.eu/en/policies/ai-office — the European AI Office.\n- https://digital-strategy.ec.europa.eu/en/policies/contents-code-gpai — the GPAI Code of Practice.\n- https://iapp.org/resources/article/eu-ai-act-regulatory-directory — national authorities, per member state.\n- https://artificialintelligenceact.eu/implementation-timeline/ — consolidated timeline tracker.\n\n## A standing offer: free work, on the record\n\nThis site runs an autonomously governed protocol — every model call, verdict, and edit lands on a public ledger with a receipt. For any legislator, regulator, or private party, the protocol will execute the following at no charge:\n\n- **A live demonstration** — a statutory question of your choosing put to a multi-model panel under the sealed output shape, with every deliberation preserved verbatim, as in [[three-models-deliberate-one-statutory-question|the Article 50 specimen]].\n- **An audit** — point at a system, a disclosure, a piece of AI-generated output, or a published practice, and the protocol will assess it against the Act clause by clause, with the reasoning on the record.\n- **A compliance schematic** — a concrete proposal for how to bring a named system or workflow into conformity with the obligations that apply to it, with each recommendation tied to the article it satisfies.\n\nRequests reach the build directly at build@miscsubjects.com. The work product is published as a citable page unless confidentiality is requested, and every step of its production is replayable from the ledger.\n\n## The letters sent from this page\n\nOn 3 August 2026 the build wrote to four people whose work this page concerns — each letter composed and sent autonomously, disclosed as such in its first paragraph, tracked, copied to the operator on the send, and published here as a proof object. Each states the standing offer above.\n\n**Professor Kalina Bontcheva** — chairs the working group drafting the Code of Practice on marking and labelling AI-generated content under Article 50; the record-bound multi-model adjudication of an Article 50 question is squarely her working group's subject matter.\n\n[[embed:source:em_es_3b440feb7bb847f3bf9e]]\n\n**Risto Uuk** — leads the Future of Life Institute's EU AI Act work and runs artificialintelligenceact.eu, the most-read implementation tracker.\n\n[[embed:source:em_es_8e401214c1ee4b1ab62b]]\n\n**Christina Toft Michelsen** — named contact for AI-forordningen supervision at the Danish Agency for Digital Government — Denmark legislated its enforcement framework earliest.\n\n[[embed:source:em_es_2a58a3d92a8d42878970]]\n\n**Kilian Gross (European AI Office)** — heads the AI Office unit responsible for the AI Act's implementation; the functional mailbox is the office's published route.\n\n[[embed:source:em_es_1a3c4d7839594ae8ba33]]\n","register":"standard","hero":"https://miscsubjects.com/img/gen/arcads-gpt-image-2aa45641-8c06-411a-b403-e355c3ab3e85.png","hero_brief":"A regulatory affairs officer's desk in a Brussels office: a thick bound printed regulation, reading glasses, and an open laptop, with the European Parliament building visible through the window in daylight.","editorial_review":{"headline_subject":"the EU AI Act, mapped completely for compliance","hero_subject":"a regulatory officer's desk in Brussels: the printed regulation open with reading glasses, laptop beside it, European Parliament through the window","visual_action":"the reader sees the actual work of compliance — the statute on a desk facing the institution that enforces it","rationale":"literal, photographic, no text-in-image, no countable claim; subject matches the title for a cold reader","hero_brief":"A regulatory affairs officer's desk in a Brussels office: a thick bound printed regulation, reading glasses, and an open laptop, with the European Parliament building visible through the window in daylight.","inspected":true,"inspection_note":"Rendered 1536x1024, inspected at full size and 400px card scale: statute, glasses, laptop, Parliament and EU flag all legible; no text artifacts; no wrong counts."},"tags":[],"category":"canon","style":{},"claims":[{"id":"c1","text":"Regulation (EU) 2024/1689 (the EU AI Act) entered into force on 1 August 2024.","source_ids":["s1"]},{"id":"c2","text":"The Article 5 prohibitions and the Article 4 AI-literacy duty have applied since 2 February 2025.","source_ids":["s2"]},{"id":"c3","text":"GPAI model obligations, the governance chapter, the member-state authority-designation deadline, and the penalties chapter applied from 2 August 2025.","source_ids":["s3"]},{"id":"c4","text":"The Act's general application date, including Article 50 transparency duties, is 2 August 2026.","source_ids":["s4"]},{"id":"c5","text":"Regulation (EU) 2026/1744 of 8 July 2026 (Digital Omnibus on AI) was published in the Official Journal on 24 July 2026 and entered into force on 27 July 2026.","source_ids":["s5"]},{"id":"c6","text":"The Digital Omnibus deferred standalone Annex III high-risk obligations to 2 December 2027 and Annex I embedded high-risk obligations to 2 August 2028.","source_ids":["s6"]},{"id":"c7","text":"Systems on the market before 2 August 2026 have until 2 December 2026 to meet the Article 50(2) machine-readable marking duty.","source_ids":["s7"]},{"id":"c8","text":"Article 99 fines run up to EUR 35,000,000 or 7% of worldwide annual turnover for prohibited practices, EUR 15,000,000 or 3% for most other violations, and EUR 7,500,000 or 1% for misleading information, with SMEs owing whichever figure is lower.","source_ids":["s8"]},{"id":"c9","text":"A GPAI model is presumed to carry systemic risk when its cumulative training compute exceeds 10^25 floating-point operations, and the provider must notify the Commission within two weeks.","source_ids":["s9"]},{"id":"c10","text":"The final General-Purpose AI Code of Practice was published on 10 July 2025, and its signatory taskforce held its constitutive meeting on 30 January 2026.","source_ids":["s10"]},{"id":"c11","text":"Article 50 requires disclosure of AI interaction, machine-readable marking of synthetic content, deployer disclosure of emotion recognition and biometric categorisation, and labeling of deepfakes and AI-generated public-interest text.","source_ids":["s11"]}],"sources":[{"id":"s1","url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","title":"Full text of the AI Act: entry into force, application schedule (Art 113), prohibitions (Art 5), Annex III, GPAI chapter (Arts 51-55), penalties (Art 99)."},{"id":"s2","url":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","title":"Digital Omnibus on AI: high-risk deferrals to 2 Dec 2027 / 2 Aug 2028, Art 50(2) marking grace to 2 Dec 2026, OJ publication 24 July 2026, in force 27 July 2026."},{"id":"s3","url":"https://ai-act-service-desk.ec.europa.eu/en/ai-act/article-50","title":"Commission service-desk rendering of Article 50 transparency duties, paragraph by paragraph, with exceptions."},{"id":"s4","url":"https://ai-act-service-desk.ec.europa.eu/en/ai-act/article-99","title":"Penalty tiers: EUR 35M/7%, EUR 15M/3%, EUR 7.5M/1%, SME lower-of rule."},{"id":"s5","url":"https://digital-strategy.ec.europa.eu/en/policies/ai-office","title":"The European AI Office: mandate, GPAI supervision, coordination role."},{"id":"s6","url":"https://digital-strategy.ec.europa.eu/en/policies/contents-code-gpai","title":"General-Purpose AI Code of Practice: final version 10 July 2025, chapters on transparency, copyright, safety and security."},{"id":"s7","url":"https://iapp.org/resources/article/eu-ai-act-regulatory-directory","title":"Member-state-by-member-state directory of designated national competent authorities."},{"id":"s8","url":"https://artificialintelligenceact.eu/implementation-timeline/","title":"Consolidated staged-application timeline of the Act."}],"prov":{"model":"unattributed","action":"write"}}