Privacy, security and AI governance across 50+ jurisdictionsTalk to us
Featured jurisdictionIndia, DPDP Act 2023

Notice, consent, Data Fiduciary duties, SDF obligations and breach intimation, explained.

Open the guide
Where most engagements startA readiness assessment, then a plan

We scope against the laws that actually apply to you, then sequence the work by risk.

Start the assessment
Featured whitepaperThe DPDP implementation clock

What must be operational before the substantive obligations commence in 2027.

Read the briefing
Free, no sign-upCheck your readiness in 10 minutes

Answer 18 questions and get a prioritised control roadmap instantly.

Start the assessment
Free, alwaysZero to practitioner

Track 01 assumes no prior knowledge of governance, risk and compliance.

Start Track 01
European Union · Regulation (EU) 2024/1689

Product safety law, applied to artificial intelligence.

The AI Act is not a privacy law. It is a risk-tiered product regulation that asks what an AI system does, how badly it can go wrong, and who is accountable when it does. It reaches providers and deployers outside the EU wherever the output is used in the Union, and as of 2 August 2026 the main obligations apply in full.

Applicability

Extraterritorial reach and the role that defines your duties

The AI Act applies to providers placing AI systems on the EU market or putting them into service in the Union irrespective of where they are established, to deployers located in the Union, and to providers and deployers in third countries where the output produced by the system is used in the Union. Importers, distributors, product manufacturers and authorised representatives carry their own defined duties.

Provider

Develops an AI system or general-purpose AI model, or has one developed, and places it on the market or puts it into service under its own name or trade mark. Carries the heaviest obligations, including conformity assessment and post-market monitoring for high-risk systems.

Deployer

Uses an AI system under its own authority in the course of a professional activity. Duties centre on using the system per instructions, assigning competent human oversight, monitoring operation, keeping logs, informing affected people and, in defined cases, the fundamental rights impact assessment.

Role reversal

A deployer becomes a provider if it puts its name or trade mark on a high-risk system already on the market, substantially modifies it, or modifies its intended purpose such that it becomes high-risk. This is the most common way an organisation acquires obligations it did not plan for.

Out of scope

Systems used exclusively for military, defence or national security purposes, scientific research and development, pure personal non-professional use, and AI released under free and open-source licences except where prohibited, high-risk or subject to the transparency rules.

AI literacy

Article 4 requires providers and deployers to take measures to ensure a sufficient level of AI literacy among staff and others operating systems on their behalf, taking account of their technical knowledge, experience, education and the context of use. This has applied since 2 February 2025.

Governance

The Commission’s AI Office supervises general-purpose AI models. Member State market surveillance authorities supervise AI systems, supported by the AI Board, a scientific panel and an advisory forum.

Classification

Four tiers, and what falls in each

Risk tiers under the AI Act
TierWhat it coversConsequence
UnacceptableArticle 5 prohibitions: harmful subliminal or manipulative techniques, exploitation of vulnerabilities, social scoring by or on behalf of public authorities, individual criminal-offence risk prediction based solely on profiling or personality traits, untargeted scraping of facial images to build recognition databases, emotion inference in the workplace and education outside medical or safety grounds, biometric categorisation to infer sensitive attributes, and real-time remote biometric identification in publicly accessible spaces for law enforcement outside narrow authorised exceptions.Banned outright since 2 February 2025. Up to EUR 35 million or 7 percent of worldwide turnover.
High-riskTwo routes. Annex I: AI as a safety component of, or itself, a product covered by EU sectoral product legislation requiring third-party conformity assessment. Annex III: biometrics, critical infrastructure, education and vocational training, employment and worker management, access to essential public and private services including creditworthiness and life and health insurance pricing, law enforcement, migration and border control, and administration of justice and democratic processes.Full compliance programme and conformity assessment. Article 6(3) allows a documented derogation where the system does not pose a significant risk, but profiling of natural persons is always high-risk.
Limited riskTransparency obligations under Article 50: disclose that a person is interacting with an AI system, mark synthetic audio, image, video or text in a machine-readable format, disclose emotion recognition and biometric categorisation to exposed persons, and label deep fakes.Disclosure and machine-readable marking rather than a conformity assessment.
Minimal riskEverything else, such as spam filters, inventory optimisation and AI in video games.No mandatory obligations. Voluntary codes of conduct are encouraged.

High-risk systems

The provider obligation set, and what deployers owe

Risk management system

A continuous, iterative process across the lifecycle identifying and evaluating reasonably foreseeable risks to health, safety and fundamental rights, and adopting targeted mitigation.

Data and data governance

Training, validation and testing sets must be relevant, sufficiently representative and to the best extent possible free of errors and complete for the intended purpose, with examination for bias and documented provenance.

Technical documentation

Prepared before placing on the market and kept current, demonstrating conformity and giving authorities the information to assess it. Annex IV sets the minimum content.

Record-keeping

Automatic logging of events over the lifetime of the system, at a level appropriate to the intended purpose, retained by the deployer for at least six months unless other law says otherwise.

Transparency to deployers

Instructions for use enabling the deployer to interpret output and use it appropriately, including characteristics, capabilities, limitations, expected accuracy and known risks.

Human oversight

Designed so it can be effectively overseen by natural persons, who can understand capacity and limits, remain alert to automation bias, interpret output correctly, decide not to use it and intervene or stop it.

Accuracy, robustness, cybersecurity

Appropriate levels across the lifecycle, resilient to errors and to attempts to alter use or performance, including protection against data poisoning, model poisoning, adversarial examples and model evasion.

Quality management system

A documented QMS covering regulatory compliance strategy, design and verification, testing, data management, post-market monitoring, incident reporting and accountability.

Registration and conformity

Annex III systems registered in the EU database before placing on the market or putting into service, with the relevant conformity assessment completed and the CE marking affixed.

Deployer duties are distinct. Use per instructions, assign oversight to competent and trained people with authority to intervene, ensure input data is relevant and representative, monitor operation and suspend and report where risk emerges, retain logs, inform workers before putting a workplace system into service, tell individuals when a high-risk system is used in decisions about them, and complete an Article 27 fundamental rights impact assessment where you fall within its scope.

General-purpose AI

Baseline duties, and the systemic-risk overlay

All GPAI providers

Maintain and keep current technical documentation of the model, including training and testing process and evaluation results. Provide information and documentation to downstream providers integrating the model. Put in place a policy to comply with EU copyright law, including reservation of rights under the text and data mining exception. Publish a sufficiently detailed summary of the content used for training, using the AI Office template.

Open-source relief

Providers of models released under a free and open-source licence with publicly available parameters, architecture and usage information are relieved of the documentation duties, but not of the copyright policy or training-content summary, and not at all if the model carries systemic risk.

Systemic-risk models

Presumed where cumulative training compute exceeds 10^25 floating point operations, or on Commission designation. Additional duties: state-of-the-art model evaluation including adversarial testing, assessment and mitigation of systemic risks at Union level, tracking and reporting serious incidents and corrective measures to the AI Office and national authorities without undue delay, and adequate cybersecurity for the model and its physical infrastructure.

Notification duty

A provider whose model meets the compute threshold must notify the Commission without delay and in any event within two weeks of meeting or knowing it will meet it. A provider may argue the model exceptionally does not present systemic risk, but the Commission decides.

Codes of practice

Adherence to a Commission-approved code of practice is the principal route to demonstrate compliance pending harmonised standards, and the General-Purpose AI Code of Practice serves that function.

Third-country providers

Providers established outside the Union must appoint an authorised representative in the Union by written mandate before placing a general-purpose AI model on the EU market.

Dates

A staged application, now largely complete

Application timeline
DateWhat appliedStatus as at 21 September 2026
1 August 2024Entry into force of Regulation (EU) 2024/1689.In force
2 February 2025Chapter I general provisions, the Article 5 prohibitions and the Article 4 AI literacy duty.Applies
2 August 2025General-purpose AI model obligations, governance and notifying authorities, confidentiality and most of the penalty regime. Models already on the market before this date have until 2 August 2027 to comply.Applies
2 August 2026General application of the Regulation, including the Annex III high-risk regime and the Article 50 transparency obligations. Member States must have at least one operational AI regulatory sandbox.Applies
2 August 2027High-risk AI that is a safety component of, or is itself, a product under the Annex I sectoral legislation. Also the deadline for pre-existing general-purpose AI models.Pending
31 December 2030Legacy AI components of large-scale EU IT systems in the area of freedom, security and justice placed on the market before 2 August 2027.Pending

Interaction

Where the AI Act and the GDPR meet

The two regimes are cumulative. The GDPR governs the processing of personal data; the AI Act governs the system. Work done for one produces evidence for the other, but neither discharges the other. For a plain-language explanation of the underlying technology, see our AI explained guide.

DPIA and FRIA

A GDPR data protection impact assessment and an Article 27 fundamental rights impact assessment are different instruments with overlapping inputs. Article 27 expressly allows the FRIA to complement an existing DPIA rather than duplicate it, so build one evidence base and two outputs.

Automated decisions

GDPR Article 22 gives individuals rights over solely automated decisions with legal or similarly significant effects. The AI Act adds a right under Article 86 to an explanation of the role of a high-risk system in decision-making. Expect both to be invoked together.

Training data

Lawful basis, purpose limitation, special-category conditions and transparency remain GDPR questions. The AI Act adds representativeness, bias examination and provenance. The Article 10(5) allowance to process special categories strictly for bias detection and correction is narrow and heavily conditioned.

Transparency

Article 50 disclosure and deep fake labelling sit alongside GDPR Articles 13 and 14 notices. Combined notices are practical, but do not let AI disclosure quietly replace processing transparency.

Implementation

Where to start

1

Inventory and classify

Build a register of AI systems and models in use, in development and embedded in procured software. Classify each against the four tiers and record the reasoning, including any Article 6(3) derogation.

2

Fix your role per system

Provider, deployer, importer or distributor, decided system by system. Flag anything you rebrand, substantially modify or repurpose, because that converts you into a provider.

3

Close the prohibitions first

Emotion inference in workplace and education settings, biometric categorisation and scraped facial recognition are the practices most likely to be running unnoticed. These are already banned and carry the highest penalty.

4

Stand up governance

AI literacy training, human oversight assignments with real authority to intervene, logging and retention, incident escalation, and a FRIA process if Article 27 applies to you.

5

Re-paper the supply chain

Require Annex IV documentation, instructions for use, training-content summaries and incident cooperation from AI vendors, and mirror your obligations down to subprocessors.

Questions

Frequently asked questions

Which parts of the AI Act apply now?

Most of it. The prohibitions on unacceptable-risk practices and the AI literacy duty have applied since 2 February 2025. The general-purpose AI obligations, the governance architecture and the penalty regime have applied since 2 August 2025. The main body of the Regulation, including the Annex III high-risk regime, became generally applicable on 2 August 2026. The remaining deferral is for high-risk AI embedded as a safety component in products covered by the Annex I sectoral legislation, which runs to 2 August 2027.

Is my organisation a provider or a deployer?

A provider develops an AI system or has one developed and places it on the market or puts it into service under its own name or trade mark. A deployer uses an AI system under its own authority in a professional capacity. Most organisations are deployers, which is a materially lighter burden. But the roles can flip: if you put your own name on a third-party system, or substantially modify it, or change its intended purpose so that it becomes high-risk, you assume provider obligations for it.

What triggers the systemic-risk obligations for general-purpose AI?

A general-purpose AI model is presumed to carry systemic risk when the cumulative compute used for training exceeds 10^25 floating point operations, and the Commission may also designate a model on the basis of other criteria. Systemic-risk models attract additional duties: model evaluation including adversarial testing, systemic risk assessment and mitigation, serious-incident tracking and reporting to the AI Office, and cybersecurity protection for the model and its physical infrastructure.

When is a fundamental rights impact assessment required?

Article 27 applies to deployers of Annex III high-risk systems that are bodies governed by public law, private entities providing public services, and deployers of systems used to evaluate creditworthiness or establish credit scores, or for risk assessment and pricing in life and health insurance. It is separate from, though it may build on, a GDPR data protection impact assessment.

How do the penalties compare with the GDPR?

They are higher at the top. Engaging in a prohibited practice attracts up to 35 million euro or 7 percent of total worldwide annual turnover, whichever is higher. Most other infringements, including the high-risk obligations, attract up to 15 million euro or 3 percent. Supplying incorrect, incomplete or misleading information to authorities attracts up to 7.5 million euro or 1 percent. Proportionate caps apply to SMEs and start-ups.

Does complying with the GDPR mean I comply with the AI Act?

No. They regulate different things and both apply. The GDPR governs the processing of personal data; the AI Act governs the safety, transparency and fundamental-rights profile of the AI system itself, and applies even where no personal data is processed. In practice they interlock: your training data governance, DPIA, transparency notices and automated decision-making safeguards under the GDPR become evidence for AI Act data governance, risk management and human oversight, but they do not discharge it.

Verify

Primary sources

General information, not legal advice. Harmonised standards, Commission guidance, delegated acts and the Annex III list continue to develop, and national implementing measures vary. Verify the current text before relying on this page. Researched 21 September 2026.

Bringing AI systems into scope?

We inventory and classify AI systems, separate provider from deployer duties, and build the risk management, oversight and documentation evidence the Regulation expects.

Talk to Vedhacon