EU AI Act primer: roles, risk tiers, GPAI and deadlines
A plain-language tour of the whole Act — who it binds, how it sorts systems by risk, what general-purpose AI adds, when each part applies, and what non-compliance costs.
A plain-language tour of the EU AI Act — Regulation (EU) 2024/1689, 113 articles and 13 annexes. The Act is risk-based: the more an AI system can hurt people's health, safety or fundamental rights, the more you must do before and after you put it on the market. It regulates AI systems (and separately general-purpose AI models), and attaches duties to your role in the value chain — not just to the technology.
This is an explainer, not legal advice. Veritome structures the work and cites the articles; you and your advisers own the final call.
1 · The four operator roles
The same model can make you a provider in one deployment and a deployer in another, so the Act pins obligations to your position in the chain.
| Role | Definition | You are… | Core duties |
|---|---|---|---|
| Provider | Art. 3(3) | Developing an AI system (or having one built) and placing it on the market under your own name. | The full high-risk set — Art. 16: requirements (Art. 8–15), conformity assessment (Art. 43), DoC (Art. 47) + CE (Art. 48), registration (Art. 49). Heaviest. |
| Deployer | Art. 3(4) | Using an AI system under your own authority in a professional context. | Art. 26 — human oversight, keep logs ≥ 6 months (Art. 26(6)), inform affected workers (Art. 26(7)); a FRIA (Art. 27) for some. |
| Importer | Art. 3(6) | Placing a non-EU provider's system on the EU market. | Art. 23 — verify the provider's conformity assessment, tech docs, CE marking and EU authorised representative before placing it. |
| Distributor | Art. 3(7) | Making a system available without changing it. | Art. 24 — check CE marking + documents are present, and act on any non-conformity you learn of. Lightest. |
Role can upgrade. Under Art. 25 an importer, distributor or deployer who puts a high-risk system on the market under their own name/brand, or substantially modifies it, becomes its provider. A non-EU provider must appoint an EU authorised representative (Art. 22 for systems, Art. 54 for GPAI models). See Am I a provider or a deployer?
2 · The four risk tiers
| Tier | Test | What it means |
|---|---|---|
| Prohibited | Art. 5 | Banned outright — social scoring, manipulative techniques, untargeted facial-image scraping, most workplace/education emotion recognition, certain biometric categorisation and real-time remote identification. You cannot place it on the market or use it. |
| High-risk | Art. 6 | Either a safety component of a regulated product (Art. 6(1) + Annex I) or a use listed in Annex III (Art. 6(2)). Triggers the full requirement set (Art. 8–15) and the conformity route. |
| Transparency (limited) | Art. 50 | Interacts with people, generates synthetic content, or recognises emotions. You must disclose — tell people they're dealing with AI and label synthetic/deepfake content. |
| Minimal | — | Everything else (spam filters, game AI, inventory forecasting). No mandatory obligations; voluntary codes of conduct encouraged (Art. 95). |
The tiers layer: a minimal-risk chatbot still owes Art. 50 transparency, and a high-risk hiring tool that also generates content owes both its Annex III duties and the Art. 50 labelling duties.
3 · High-risk, in a little more detail
There are two independent routes into high-risk (Art. 6): the product route (Art. 6(1) + Annex I — a safety component of a product that needs third-party conformity assessment) and the Annex III route (Art. 6(2) — one of eight listed high-risk areas). The Art. 6(3) derogation is disjunctive: an Annex III system is not high-risk if it doesn't pose a significant risk of harm because it meets at least one of four conditions — but profiling of natural persons is always high-risk and overrides any derogation, which you must document (Art. 6(4)). See The Annex III high-risk areas and The Article 6(3) exception.
4 · General-purpose AI (GPAI) models
A GPAI model (Art. 3(63)) is regulated as a model under Chapter V (Art. 51–56), separately from the systems built on it: Art. 53 duties for all GPAI providers (technical documentation, downstream information, copyright policy, training-content summary); Art. 55 additional duties where the model carries systemic risk (Art. 51); Art. 54 for non-EU providers; Art. 56 voluntary codes of practice. If you only call a third-party GPAI API, those duties sit with the model provider. See What counts as GPAI.
5 · Key duties, by article
- Art. 9 — risk-management system (continuous, iterative). Art. 10 — data & data governance. Art. 11 + Annex IV — technical documentation. Art. 12 — logging / record-keeping. Art. 13 — instructions for use to deployers. Art. 14 — human oversight. Art. 15 — accuracy, robustness and cybersecurity.
- Art. 27 — FRIA (a deployer duty). Art. 43 — conformity assessment; Art. 47 — Declaration of Conformity (kept 10 years); Art. 48 — CE marking; Art. 49 + Annex VIII — EU-database registration.
- Art. 72 — post-market monitoring; Art. 73 — serious-incident reporting (2 / 10 / 15 calendar days from awareness).
6 · When it applies — the deadlines
The Act entered into force on 1 August 2024 and applies in stages under Art. 113:
| Date | What starts to apply |
|---|---|
| 2 Feb 2025 | Prohibited practices (Art. 5) and AI literacy (Art. 4). Already in force. |
| 2 Aug 2025 | GPAI model obligations (Art. 53 / 55), the governance bodies (AI Office / Board), and the penalty regime (Art. 99–101). |
| 2 Aug 2026 | The general date of application — Annex III high-risk systems (Art. 6(2)) and Art. 50 transparency duties. The milestone most organisations plan back from. |
| 2 Aug 2027 | High-risk safety components of regulated products — the Art. 6(1) product route — and the deadline for GPAI models already on the market before Aug 2025 to conform. |
7 · Penalties — Article 99
Fines are the higher of a fixed amount or a percentage of worldwide annual turnover: €35M / 7% for breaching the Art. 5 prohibitions; €15M / 3% for most other operator obligations; €7.5M / 1% for misleading information to authorities. For SMEs and start-ups the fine is the lower of the two (Art. 99(6)). See Penalties: what non-compliance actually costs.
Always confirm dates against the regulatory registry inside the app — it is kept current. For the quick lookup version of the terms and articles, see Glossary and FAQ.