EU AI ActFree Resource

EU AI Act Risk Tiers, Roles, and Timeline

The EU AI Act can apply when an organisation develops, sells, imports, distributes, integrates, or uses AI in the EU. It can also cover providers and deployers based outside the EU when output produced by their is used in the EU. This hub helps identify the regulated system or model, each organisation's role, and the rules that follow.

By Sorena AIUpdated 2026No signup required
Quick scan
AI Act
Current legal status
was published on 24 July 2026 and enters into force on 27 July 2026. Keep that binding amendment separate from non-binding Commission guidelines, consultations, and voluntary codes of practice.
AI system or model
A deployed chatbot, scoring feature, recommendation tool, or embedded product function is assessed as an . A reusable model offered for integration may also trigger separate duties.
Decision order
Check exclusions and territorial scope, map roles, stop prohibited uses, classify high-risk systems, assess general-purpose model duties, then add transparency and evidence requirements.

Use the visual timeline for chronology and the linked guides for the facts, roles, controls, and evidence behind each milestone.

Key dates
Art. 5
Prohibited
Annex III
High risk
Ch. V
GPAI
Art. 50
Transparency
EU AI Act questions this hub helps resolve
1. Does the Act apply?
Describe the or reusable , where it is offered or used, and where its output is used. A based outside the EU can be covered when it places a system or model on the Union market. A provider or based outside the EU can also be covered when output produced by its AI system is used in the Union. Also check the Act's specific exclusions, including purely personal non-professional use and systems used exclusively for military, defence, or national-security purposes.
2. What role do we have?
Identify who develops and brands the system, who uses it, and who imports, distributes, integrates, or modifies it. The same organisation can be a for one system and a for another.
3. Which rules follow?
Screen prohibited practices first, then each route, notices and content marking, and duties for providers of general-purpose AI models. Record the conclusion, evidence, owner, and date that applies.
Map roles
Screen risk tiers
Keep evidence
Publication details
Editorial metadata for this artifact
Author
Sorena AI
Published
Mar 4, 2026
Updated
Jul 31, 2026

Start with the real product and use case. Then check scope, actor roles, prohibited uses, high-risk classification, duties, transparency duties, and the application date for each obligation.

Common starting points

Go straight to the AI Act decision you need

Start with penalties, the amended calendar, high-risk requirements, or AI literacy under the EU Artificial Intelligence Act (AI Act). The complete guide library below covers each role, risk tier, obligation, and evidence path.

Map Article 99 penalties

is the AI Act's penalty table. Match the actor and infringement to the correct maximum tier, then check the national process, application date, and the lower ceiling where the fined business is a small or medium-sized enterprise (SME). The amounts are maximums, not automatic fines.

Review AI Act penalty tiers

Use the amended deadline calendar

Separate the 2 August 2026 general application date from the amended dates for high-risk AI systems. Sections 1 to 3 apply from 2 December 2027 to the paragraph 2 route in for uses, such as specified recruitment or credit-scoring systems, and from 2 August 2028 to the paragraph 1 route for product-related systems.

Check the current AI Act dates

Build the high-risk evidence pack

Use to decide whether the system is high-risk. If it is, require controls and evidence for risk management, data, technical documentation, logs, instructions, human oversight, accuracy, robustness, and cybersecurity.

Open the high-risk checklist

Plan AI literacy measures

AI literacy means giving people enough knowledge and skill to operate or use an responsibly in its actual setting. Providers and deployers should tailor training and instructions to the person's experience, the use case, and the people affected, then keep evidence that the measures were delivered.

Read the AI literacy answer
AI Act Timeline

Key dates for EU AI Act implementation

Apply each date to the relevant rule. Definitions and the original Article 5 prohibitions have applied since 2 February 2025, and most GPAI, governance, and penalty provisions since 2 August 2025. , published on 24 July 2026 and entering into force on 27 July 2026, keeps 2 August 2026 as the general application date but moves Sections 1-3 to 2 December 2027 for high-risk systems and 2 August 2028 for (1) product-linked systems. Its new prohibition on specified non-consensual intimate material and child sexual abuse material applies from 2 December 2026.

Loading timeline...
Recommended reading path

Choose the next AI Act decision

New to the Act? Start with scope, roles, and classification. If those decisions are already documented, jump directly to the obligation, evidence, deadline, monitoring, or comparison you need.

1

Start here: scope, roles, and risk

Establish what the product or use case is, whether the Act applies, which operator roles each organisation holds, and which risk route needs investigation.

2

Classification and obligations

Move from the initial screen into the rules for prohibited practices, high-risk systems, GPAI models, transparency, impact assessment, and penalties.

EU AI Act Article 5 Prohibited AI Practices Screening Guide
Screen AI systems against EU AI Act Article 5, including manipulation, social scoring, biometrics, law enforcement, and the new prohibited-content category.
Read guide
EU AI Act high-risk AI use cases by industry | Article 6 and Annex III guide
Industry-by-industry guide to EU AI Act high-risk classification under Article 6, Annex III, Annex I product safety routes, exclusions, and provider/deployer boundaries.
Read guide
EU AI Act high-risk requirements checklist: Articles 8-15
Checklist for EU AI Act high-risk AI system requirements in Articles 8-15: risk management, data governance, documentation, logs, transparency, human oversight, accuracy, robustness, and cybersecurity.
Read guide
EU AI Act GPAI Provider Obligations: Articles 53 and 55
Source-backed guide to EU AI Act duties for general-purpose AI model providers: Article 53 documentation, copyright policy, training-content summary, downstream information, and Article 55 systemic-risk controls.
Read guide
EU AI Act Article 50 transparency, labeling, and user disclosures
Source-backed guide to EU AI Act Article 50 duties for user interaction notices, synthetic content marking, deepfake labels, emotion recognition notices, biometric categorisation notices, and related high-risk AI instructions for use.
Read guide
EU AI Act FRIA for high-risk AI systems: Article 27 scope and evidence
Source-backed guide to EU AI Act Article 27 fundamental rights impact assessments: who must run a FRIA, Article 6(2) triggers, Annex III carveouts, DPIA overlap, notification, and registration evidence.
Read guide
EU AI Act penalties and fines: Article 99 tiers and GPAI exposure
EU AI Act penalties explained: Article 99 fine tiers, prohibited-practice exposure, incorrect information, SME caps, Member State rules, and GPAI model fines.
Read guide
3

Implementation and evidence

Translate the assigned obligations into controls, conformity decisions, technical documentation, provider evidence, and owned operating workflows.

EU AI Act Compliance Checklist by Risk Class
A practical EU AI Act checklist for classifying AI systems, assigning operator roles, screening prohibited practices, and collecting evidence for high-risk, GPAI, transparency, monitoring, and incident duties.
Read guide
EU AI Act Compliance Program: roles, high-risk evidence, GPAI and incidents
Build an EU AI Act compliance program around provider, deployer, importer, distributor, high-risk, GPAI, transparency, monitoring, and incident evidence duties.
Read guide
EU AI Act High-Risk AI Requirements: Articles 8-16 and 26
Map the EU AI Act requirements for high-risk AI systems: risk management, data governance, technical documentation, logs, transparency, human oversight, accuracy, robustness, cybersecurity, and deployer duties.
Read guide
EU AI Act Technical Documentation and Provider Evidence Templates
Build AI Act evidence templates for high-risk AI providers: Article 11 technical documentation, Annex IV fields, quality management, conformity, CE marking, registration, logs, and post-market monitoring.
Read guide
EU AI Act conformity assessment and notified bodies for high-risk AI
Source-backed guide to EU AI Act high-risk AI conformity assessment routes, provider evidence, EU declaration of conformity, CE marking, and notified body involvement.
Read guide
EU AI Act high-risk conformity assessment route selector
Select the EU AI Act Article 43 conformity assessment route for a high-risk AI system, including Annex I product legislation, Annex III categories, notified body triggers, standards, declaration, CE marking, registration, and evidence.
Read guide
EU AI Act GPAI evidence pack checklist for Article 53 and 55
Build a source-backed evidence pack for EU AI Act GPAI model obligations: technical documentation, downstream information, copyright policy, training-content summary, and systemic-risk records where applicable.
Read guide
4

Deadlines and monitoring

Sequence the staged application dates, then connect post-market monitoring and serious-incident triage to the systems and models already classified.

5

Compare frameworks or answer a specific question

See how AI Act work relates to ISO/IEC 42001 and the NIST AI RMF, or use the focused FAQ when you already know the question you need to resolve.

Next step

Turn EU AI Act classification into owned implementation work

This hub is the shared entry point for AI Act inventory, role mapping, risk-tier screening, obligation assignment, and evidence governance. Route uncertain facts into cited research and convert confirmed duties into owners, records, and release gates.

What this unlocks
  • Start with one system, model, output, supplier, or deployment context and record the EU AI Act role for each operator.
  • Use Assessment Autopilot to request risk classification evidence, technical documentation, transparency notices, GPAI records, and post-market monitoring checkpoints.
  • Use Research Copilot for cited questions about Article 5 prohibitions, high-risk categories, disclosures, Chapter V GPAI duties, and staged application dates.
  • Keep legal interpretation, engineering evidence, supplier attestations, approval history, and reassessment triggers connected to the same cited evidence file.
EU AI Act artifact preview
Share it internally
Download the timeline export to align legal, product, engineering, and commercial teams on milestones and deadlines.