VeritomeHelp Center
/

Glossary and FAQ

A quick reference for the EU AI Act terms, dates and articles that come up most often, plus answers to the questions people ask first.

Updated 15.07.2026

A quick reference for the terms, dates and articles that come up most often. For the narrative version, read the EU AI Act primer first.

Enforcement timeline

The AI Act entered into force on 1 August 2024 and applies in stages under Art. 113:

DateWhat applies
1 Aug 2024The Act enters into force. The clocks start; nothing is enforceable yet.
2 Feb 2025Prohibited practices (Art. 5) and AI literacy (Art. 4) — already in force.
2 Aug 2025GPAI model obligations (Art. 53 / 55), the governance bodies, and the penalty regime (Art. 99–101).
2 Aug 2026The general date of applicationAnnex III high-risk systems (Art. 6(2)) and Art. 50 transparency duties.
2 Aug 2027High-risk safety components of regulated products — the Art. 6(1) product route — and the deadline for GPAI models placed on the market before Aug 2025 to conform.

If you're standing up compliance now, the 2 August 2026 date is the one to plan backwards from.

Article quick-reference

Article / AnnexWhat it covers
Art. 3Definitions — provider 3(3), deployer 3(4), importer 3(6), distributor 3(7), GPAI model 3(63).
Art. 4AI literacy — all providers and deployers.
Art. 5Prohibited practices.
Art. 6High-risk classification — 6(1) product route, 6(2) Annex III, 6(3) derogation, 6(4) its documentation.
Art. 9Risk-management system.
Art. 10Data & data governance.
Art. 11 + Annex IVTechnical documentation.
Art. 13Instructions for use (IFU).
Art. 14Human oversight.
Art. 16Provider obligations.
Art. 22 / 54Authorised representative — systems / GPAI models.
Art. 23 / 24Importer / distributor obligations.
Art. 25Role changes along the chain (own-name / substantial modification).
Art. 26Deployer obligations — 26(6) logs ≥ 6 months, 26(7) inform workers.
Art. 27Fundamental-rights impact assessment (FRIA).
Art. 43 / 47 / 48Conformity assessment / Declaration of Conformity (kept 10 years) / CE marking.
Art. 49 + Annex VIIIRegistration in the EU database.
Art. 50Transparency obligations.
Art. 51–56GPAI models (Chapter V) — 53 all providers, 55 systemic risk.
Art. 72 / 73Post-market monitoring / serious-incident reporting (2 / 10 / 15 days).
Art. 99 / 113Penalties / entry into force + phased dates.

Glossary

  • AI system (Art. 3(1)) — a machine-based system that infers, from its input, how to generate outputs (predictions, content, recommendations, decisions) that can influence physical or virtual environments.
  • GPAI model (Art. 3(63)) — a general-purpose AI model trained on broad data and usable across many tasks; regulated under Chapter V (Art. 51–56).
  • Authorised representative (Art. 22 / 54) — an EU-based entity a non-EU provider appoints by written mandate to act for it under the Act.
  • Substantial modification (Art. 3(23) / Art. 25) — a change to a system after it's on the market that affects its compliance or intended purpose; can make the modifier a provider.
  • Profiling — automated processing to evaluate personal aspects of a natural person; under Art. 6(3) it makes an Annex III system always high-risk, overriding any derogation.
  • Systemic risk (Art. 51) — the classification that pulls a GPAI model into the heavier Art. 55 obligations.
  • Annex I / III / IV / VIII — product-safety legislation (6(1) route) / the eight high-risk use areas / the contents of technical documentation / the EU-database registration field set.
  • CE marking (Art. 48) / DoC (Art. 47, kept 10 years) / Conformity assessment (Art. 43, Annex VI internal control or Annex VII notified body) / Notified body / Harmonised standard.
  • FRIA (Art. 27) — fundamental-rights impact assessment, required of certain deployers of Annex III systems before first use.
  • IFU (Art. 13) — instructions for use a provider must give a deployer.
  • Post-market monitoring (Art. 72) / Serious incident (Art. 3(49) / Art. 73, reportable in 2 / 10 / 15 calendar days from awareness).
  • Market-surveillance authority — the national body that enforces the Act and receives incident notifications. AI Office — the Commission body overseeing GPAI models.

FAQ

Does the Act apply to us if we only use AI, not build it? Yes. Deployers have real duties under Art. 26 — human oversight, keeping logs ≥ 6 months, informing affected workers — and, for some, a FRIA (Art. 27). AI literacy (Art. 4) applies to every deployer regardless of tier.

We use a third-party model under our own brand. Are we a provider? Quite possibly. Placing a system on the market under your own name, or substantially modifying a high-risk one, upgrades you to provider under Art. 25.

We're based outside the EU — does the Act reach us? It can. Under Art. 2 it applies to providers placing systems on the EU market wherever established, to deployers in the Union, and where the system's output is used in the Union. A non-EU provider of a high-risk system must appoint an EU authorised representative (Art. 22).

What's the difference between prohibited and high-risk? A prohibited system (Art. 5) cannot be placed on the market or used at all. A high-risk system (Art. 6) is allowed once you meet the full requirement set, pass conformity assessment, and register it. Prohibited is a ban; high-risk is a licence with conditions.

Is "minimal risk" the same as "exempt"? There are no mandatory obligations for minimal-risk systems, but Art. 50 transparency can still apply if it's a chatbot or generates content, and Art. 4 literacy applies to every operator.

Do the GPAI obligations apply if we just call an API? No — the Chapter V duties sit with the model provider. You inherit the downstream information they must give you, and may still owe Art. 50 transparency on the system you build. Only if you train or release a GPAI model do Art. 53 (and, for systemic risk, Art. 55) fall on you.

Is a FRIA the same as a GDPR DPIA? No. A FRIA (Art. 27) assesses impacts on fundamental rights and is a deployer duty for certain Annex III systems; a DPIA (GDPR Art. 35) assesses data-protection risk. They overlap and can reference each other, but one does not discharge the other.

Do we have to register every AI system in the EU database? No — Art. 49 registration is for high-risk systems (and certain Annex III deployers). Keeping your own internal inventory, though, is expected of everyone.

Does Aria's classification count as our decision? No. Aria proposes; a human confirms. The confirmed decision — with who confirmed it — is what lands in your audit trail.

Need to act on this?Open Veritome