Decloak is an AI-powered web security intelligence platform that scans a site's HTTP/TLS posture, JavaScript, and third-party scripts to produce a report anyone can read. This guide is part of Decloak's library of practical, source-backed security guidance.
In this guide
- Key takeaways
- What is the official reference for the EU AI Act?
- Which entities are covered by the EU AI Act?
- How does the EU AI Act define an “AI system”?
- What are the four risk - based classifications and their obligations?
- Which AI practices are explicitly prohibited?
- What obligations do high - risk AI providers face?
- What must be included in the technical documentation?
- How are general - purpose AI models regulated?
- When does a GPAI model become a systemic - risk candidate?
- What are the key implementation timelines?
- What penalties can be imposed for non - compliance?
- Which bodies enforce the EU AI Act?
- When do transparency obligations for interacting AI systems start?
- How should a provider set up post - market monitoring?
- What data - governance steps are required?
Key takeaways
- The EU AI Act (Regulation 2024/1689) applies to any AI system or general - purpose AI model placed on the EU market, regardless of the provider’s location.
- AI systems are classified into four risk levels; high - risk systems require a risk - management system, technical documentation, CE - marking, and post - market monitoring.
- Prohibited practices include social - scoring, real - time biometric identification in public spaces, and generation of non - consensual intimate material.
- General - purpose AI models that exceed 10²⁵ FLOPs are deemed systemic - risk and trigger extra obligations.
- Full enforcement starts on 2 Aug 2026; fines can reach 30 % of annual turnover.
What is the official reference for the EU AI Act?
The act is formally known as Regulation (EU) 2024/1689, published in the Official Journal L 2024/1689 on 13 June 2024. All legal citations should reference this document.
Which entities are covered by the EU AI Act?
The regulation applies to any provider that places an AI system or a general - purpose AI (GPAI) model on the Union market or puts it into service, and to any deployer that uses such systems in the EU, regardless of where the provider is established.
How does the EU AI Act define an “AI system”?
An AI system is a machine - based system that can operate with varying autonomy, may adapt after deployment, and generates outputs (predictions, content, recommendations, decisions) that can affect physical or virtual environments. The definition contains seven elements, but not all must be present at all times.
What are the four risk - based classifications and their obligations?
- Unacceptable risk - outright prohibited (e.g., social - scoring, real - time remote biometric identification in public spaces).
- High risk - must undergo conformity assessment, obtain a CE mark, produce technical documentation, and implement post - market monitoring.
- Limited risk - requires transparency information for users.
- Minimal risk - no specific obligations.
Which AI practices are explicitly prohibited?
The act lists nine prohibited practices, including:
- Manipulation or deception that causes harm.
- Exploitation of vulnerabilities.
- Social - scoring of individuals.
- Biometric categorisation for protected characteristics.
- Real - time remote biometric identification for law - enforcement in public spaces.
- Emotion - recognition in workplaces or education.
- Untargeted scraping for facial - recognition databases.
- Generation of non - consensual intimate material.
- Generation of child - sexual - abuse material.
What obligations do high - risk AI providers face?
High - risk providers must:
- Implement a risk - management system (Art. 9).
- Ensure data - governance (Art. 10).
- Compile technical documentation covering at least 14 elements (Annex IV).
- Conduct conformity assessment and issue an EU Declaration of Conformity (Art. 47).
- Affix the CE mark.
- Set up post - market monitoring (Art. 72 - 73).
What must be included in the technical documentation?
Technical documentation must contain, at minimum:
- System description and intended purpose.
- Design and development details.
- Data - set information and governance.
- Risk - management records.
- Testing and validation results.
- Cybersecurity measures.
- Bias and accuracy monitoring.
- User instructions.
- Post - market monitoring plan.
- List of harmonised standards. (plus four additional required elements).
How are general - purpose AI models regulated?
Providers of GPAI models must supply a general description (tasks, architecture, parameters, modality, licence) and detailed development information (training methodology, data provenance, computational resources, energy consumption). Downstream providers must also receive this information.
When does a GPAI model become a systemic - risk candidate?
Any model that required ≥ 10²⁵ floating - point operations (FLOPs) to train is presumed systemic - risk. Providers must notify the European Commission, perform additional risk - assessment, conduct adversarial testing, and report incidents.
What are the key implementation timelines?
- 1 Aug 2024 - Act entered into force.
- 2 Feb 2025 - Prohibited practices and AI - literacy obligations apply.
- 2 Aug 2025 - Governance rules for GPAI start.
- 2 Aug 2026 - Full enforcement begins (AI Office operational, CE - marking for high - risk, transparency for interacting systems).
- 2 Dec 2027 - Strict conformity - assessment for high - risk AI systems.
- 2 Aug 2028 - Extended transition for high - risk AI embedded in regulated products.
What penalties can be imposed for non - compliance?
Administrative fines may reach up to 30 % of the offending company’s annual turnover (or a higher fixed amount). SMEs and start - ups face proportionally lower fines.
Which bodies enforce the EU AI Act?
- AI Office (European Commission) - central coordinator, regulator for GPAI, can request documentation and issue corrective measures.
- National competent authorities - conduct market surveillance and enforce at the Member - State level.
- AI Board - advisory panel of experts.
When do transparency obligations for interacting AI systems start?
Providers must inform users that they are interacting with AI (Art. 50) from 2 Aug 2026. Systems placed before that date have a grace period until 2 Dec 2026.
How should a provider set up post - market monitoring?
Providers must establish a monitoring system that collects performance data from deployers, reports serious incidents to the AI Office, and feeds the results back into the risk - management process.
What data - governance steps are required?
Providers must ensure data quality, relevance, and representativeness, and document all data - management procedures, including bias mitigation strategies.
All facts are drawn from Regulation 2024/1689 and the EU’s official implementation guides hosted on Eur - Lex and the European Commission AI Act Service Desk.
Related guides
What is NIST in cybersecurity and why should you care?
NIST is the U.S. agency that creates the Cybersecurity Framework and a suite of standards like SP 800 - 53 that guide risk management for both government and private organizations.
Which NIST Cybersecurity Standards Should My Organization Adopt in 2024 - 2025?
Learn the core NIST publications that form a practical, layered security program, how they map together, and concrete steps to start using them today.
Does the EU AI Act apply to U.S. companies?
Yes - the EU AI Act has extraterritorial reach and can bind U.S. AI providers, deployers, importers or distributors whenever their systems are placed on the EU market, used by an EU entity, or produce output that is used in the Union.