Back to Guides
Guide16 September 2026

What You Need to Know About the EU AI Act from Eur - Lex

Decloak is an AI-powered web security intelligence platform that scans a site's HTTP/TLS posture, JavaScript, and third-party scripts to produce a report anyone can read. This guide is part of Decloak's library of practical, source-backed security guidance.

In this guide
  1. Key takeaways
  2. What is the official reference for the EU AI Act?
  3. Which entities are covered by the EU AI Act?
  4. How does the EU AI Act define an “AI system”?
  5. What are the four risk - based classifications and their obligations?
  6. Which AI practices are explicitly prohibited?
  7. What obligations do high - risk AI providers face?
  8. What must be included in the technical documentation?
  9. How are general - purpose AI models regulated?
  10. When does a GPAI model become a systemic - risk candidate?
  11. What are the key implementation timelines?
  12. What penalties can be imposed for non - compliance?
  13. Which bodies enforce the EU AI Act?
  14. When do transparency obligations for interacting AI systems start?
  15. How should a provider set up post - market monitoring?
  16. What data - governance steps are required?

Key takeaways

What is the official reference for the EU AI Act?

The act is formally known as Regulation (EU) 2024/1689, published in the Official Journal L 2024/1689 on 13 June 2024. All legal citations should reference this document.

Which entities are covered by the EU AI Act?

The regulation applies to any provider that places an AI system or a general - purpose AI (GPAI) model on the Union market or puts it into service, and to any deployer that uses such systems in the EU, regardless of where the provider is established.

How does the EU AI Act define an “AI system”?

An AI system is a machine - based system that can operate with varying autonomy, may adapt after deployment, and generates outputs (predictions, content, recommendations, decisions) that can affect physical or virtual environments. The definition contains seven elements, but not all must be present at all times.

What are the four risk - based classifications and their obligations?

Which AI practices are explicitly prohibited?

The act lists nine prohibited practices, including:

  1. Manipulation or deception that causes harm.
  2. Exploitation of vulnerabilities.
  3. Social - scoring of individuals.
  4. Biometric categorisation for protected characteristics.
  5. Real - time remote biometric identification for law - enforcement in public spaces.
  6. Emotion - recognition in workplaces or education.
  7. Untargeted scraping for facial - recognition databases.
  8. Generation of non - consensual intimate material.
  9. Generation of child - sexual - abuse material.

What obligations do high - risk AI providers face?

High - risk providers must:

What must be included in the technical documentation?

Technical documentation must contain, at minimum:

  1. System description and intended purpose.
  2. Design and development details.
  3. Data - set information and governance.
  4. Risk - management records.
  5. Testing and validation results.
  6. Cybersecurity measures.
  7. Bias and accuracy monitoring.
  8. User instructions.
  9. Post - market monitoring plan.
  10. List of harmonised standards. (plus four additional required elements).

How are general - purpose AI models regulated?

Providers of GPAI models must supply a general description (tasks, architecture, parameters, modality, licence) and detailed development information (training methodology, data provenance, computational resources, energy consumption). Downstream providers must also receive this information.

When does a GPAI model become a systemic - risk candidate?

Any model that required ≥ 10²⁵ floating - point operations (FLOPs) to train is presumed systemic - risk. Providers must notify the European Commission, perform additional risk - assessment, conduct adversarial testing, and report incidents.

What are the key implementation timelines?

What penalties can be imposed for non - compliance?

Administrative fines may reach up to 30 % of the offending company’s annual turnover (or a higher fixed amount). SMEs and start - ups face proportionally lower fines.

Which bodies enforce the EU AI Act?

When do transparency obligations for interacting AI systems start?

Providers must inform users that they are interacting with AI (Art. 50) from 2 Aug 2026. Systems placed before that date have a grace period until 2 Dec 2026.

How should a provider set up post - market monitoring?

Providers must establish a monitoring system that collects performance data from deployers, reports serious incidents to the AI Office, and feeds the results back into the risk - management process.

What data - governance steps are required?

Providers must ensure data quality, relevance, and representativeness, and document all data - management procedures, including bias mitigation strategies.


All facts are drawn from Regulation 2024/1689 and the EU’s official implementation guides hosted on Eur - Lex and the European Commission AI Act Service Desk.

Free security scan

See what's actually exposed on your site.

Decloak's free scan runs in about 15 seconds, no account required, and covers:

  • HTTP/TLS security posture
  • JavaScript CVEs
  • Exposed Supabase/Lovable/Base44 misconfigurations
  • AI-written executive summary