Project CognivoraEducation that fits life

Regulation (EU) 2024/1689

The EU AI Act,
explained.

The world's first comprehensive law on artificial intelligence. 113 articles, thirteen annexes, and a great deal of confusion. This page is the short version: why it exists, whether it applies to you, and what it actually asks of you.

Adopted 13 June 2024 Published in the Official Journal of the European Union as Regulation (EU) 2024/1689. Shared here by Project Cognivora; this is not an EU publication.

113 articles 13 annexes 180 recitals In force since 1 August 2024

Why this law exists

Because trust does not scale on its own.

AI can now produce a face, a voice or a decision that is hard to tell apart from the real thing. That breaks something people rely on without thinking about it: the assumption that what you see, hear and are told is roughly what it appears to be.

The EU's answer is not to slow the technology down. It is to make the risky uses visible and accountable, and to leave everything else alone. Most AI in everyday use is untouched by this law. A small slice of it is regulated heavily, and a narrow band is banned outright.

The result is a law that asks a single question about any system: what could go wrong for a person, and how badly?

Who it applies to

Probably you, but less than you fear.

The Act does not care what you call yourself. It cares what you do with the system, and where the people affected by it are.

Role 1

Provider

You develop an AI system, or have one developed, and place it on the market under your own name. Most obligations sit here.

Watch out: you can become a provider without meaning to. Take a general-purpose system and use it for a high-risk purpose, and Article 25 can make you the provider of that system.

Role 2

Deployer

You use an AI system under your own authority in a professional context. This is where most organisations sit, and where most people are surprised to find themselves.

A recruiter using a screening tool, a school using a grading assistant, a company putting an AI photo on its website: all deployers.

It applies outside the EU too

The Act follows the people, not the company. If the output of your system is used in the Union, it is in scope, wherever you are based. That is why American and British providers have been adjusting for two years.

What each category means

The practical consequences.

Unacceptable risk

Banned. No exceptions for good intentions.

Article 5 lists eight practices that may not be placed on the market or used at all. Among them:

  • Subliminal or manipulative techniques that materially distort behaviour
  • Exploiting vulnerability due to age, disability or social situation
  • Social scoring leading to unjustified detrimental treatment
  • Predicting criminal behaviour from profiling alone
  • Untargeted scraping of facial images to build recognition databases
  • Emotion recognition in the workplace and in education
Applies since 2 February 2025
High risk

Allowed, but you carry the weight.

AI that helps decide things that shape a person's life: recruitment, credit, education, essential services, law enforcement. Permitted, with a substantial compliance regime.

  • Risk management system and data governance
  • Technical documentation and automatic logging
  • Meaningful human oversight, by someone with real authority
  • Accuracy, robustness and cybersecurity
  • Conformity assessment, CE marking, EU database registration
  • For deployers: instructions, monitoring, six months of logs, and informing workers' representatives before use
Annex III from 2 December 2027 · Annex I from 2 August 2028
Limited risk

Just be honest about what it is.

No approval, no documentation, no audit. One duty: if AI could fool someone about what is real or who they are dealing with, say so.

  • Chatbots must reveal that they are AI, unless that is obvious
  • Generated image, audio, video and text must carry a machine-readable mark (a duty on the provider, not on you)
  • Deepfakes must be disclosed by whoever publishes them
  • The disclosure must be clear and given at the latest at first exposure
Applies since 2 August 2026
Minimal risk

Carry on.

Spam filters, recommendation engines, AI in games, inventory forecasting, translation. By far the largest group in practice.

No risk-based obligations under the AI Act. Everything else still applies: data protection, consumer law, copyright, sector rules. A classification under this Act is not a clean bill of health under any other.

No specific date. Nothing to do.

Ask a question

Not sure where you fit?

Describe what you are building or using, and get an answer grounded in the regulation text rather than in vibes.

EU AI Act assistant
You are talking to an AI assistant, not a human. Answers are based on Regulation (EU) 2024/1689 and European Commission guidance. This is information, not binding legal advice.

Try one of these, or ask your own:

Always check the source before a decision that matters.

Go deeper

Podcasts, a quiz, videos and documents.

We are building a small library around this page. Everything here is made to be used, not admired.

Listen

The podcast

One part of the Act per episode, worked through by two hosts. Episode 1 covers the question almost everyone gets wrong: whether the Act applies to you at all.

Maya and Sam are AI-generated voices. They are not real people and the episode is not a recording of a conversation that took place. The music is generated too. Every word of the script was written and edited by a human, who carries editorial responsibility for it.

The sources

Not everything called “guidance” carries the same weight.

This is the part most summaries skip. A regulation binds you. A Commission guideline tells you how they will read it. A code of practice is voluntary. Knowing which is which changes what you can rely on.

Made by us

Ours, not official

Our own reading of the sources above, put in a form you can use. It carries no legal weight of its own, so check anything decisive against the regulation itself.

Where to start

Find out which category you are in before you build the thing.

Most compliance problems are design decisions that were made without knowing they were compliance decisions. The cheapest moment to get this right is now.

Get in touch

About this page. Written by Project Cognivora on the basis of Regulation (EU) 2024/1689 and guidance published by the European Commission. Some of that guidance is still in draft, and the consolidated text of the regulation including the AI Omnibus amendments was not yet published at the time of writing. Dates and article numbers were checked against official sources on 27 August 2026.

This is information, not binding legal advice. Have a lawyer or the competent authority review anything involving a possible prohibition, a high-risk classification, or a significant impact on people.