What is the EU AI Act?
The AI Act sets harmonised rules for AI systems placed on the market or used in the EU. Like GDPR, it reaches companies outside the EU when their AI systems, or the output of those systems, are used in the EU.
It separates roles. Providers develop an AI system, or have one developed, and place it on the market under their name. Deployers use an AI system in a professional setting. Most obligations sit with providers, but deployers have duties too.
The four risk levels
Risk level
UnacceptableExamples
Social scoring, manipulative AI, emotion recognition at work or schoolWhat it means
Banned since 2 February 2025Risk level
HighExamples
AI in hiring, credit scoring, education and essential services, and safety parts of regulated productsWhat it means
Strict requirements before and after the system reaches the marketRisk level
Limited (transparency)Examples
Chatbots, deepfakes, AI-generated contentWhat it means
People must be told they are dealing with AI, or that content is AI-generatedRisk level
MinimalExamples
Spam filters, AI in video gamesWhat it means
No new obligationsGeneral-purpose AI models, such as the large language models behind many chatbots, have a separate set of rules for the companies that provide them.
When each part applies
Date
2 February 2025What applies
Banned practices and AI literacyReference
Art. 5, Art. 4Date
2 August 2025What applies
General-purpose AI models, governance and penaltiesReference
Art. 53 to 55, Art. 99Date
2 August 2026What applies
Transparency obligationsReference
Art. 50Date
2 December 2027What applies
High-risk systems listed in Annex IIIReference
Annex IIIDate
2 August 2028What applies
High-risk AI in regulated productsReference
Annex IThe high-risk dates were moved back by the Digital Omnibus on AI, Regulation (EU) 2026/1744, in force since 27 July 2026. It is a delay, not a cancellation. AI systems already on the market before 2 August 2026 have until 2 December 2026 to add machine-readable marking to the content they generate.
What high-risk AI systems must do
- A risk management system across the whole life cycle (Article 9).
- Data governance: training data that is relevant, representative and examined for bias (Article 10).
- Technical documentation (Article 11) and automatic logging (Article 12).
- Transparency and instructions for use for deployers (Article 13).
- Human oversight that lets people understand, intervene in and override the system (Article 14).
- Accuracy, robustness and cybersecurity (Article 15).
- A quality management system (Article 17), a conformity assessment and registration before the system reaches the market.
Deployers of high-risk systems must use them according to their instructions, assign human oversight, monitor them and keep their logs. Some deployers must also carry out a fundamental rights impact assessment (Article 27).
EU AI Act fines
Breach
Banned AI practicesMaximum fine
€35M or 7% of worldwide annual turnoverReference
Art. 99(3)Breach
Most other obligations, including high-risk and transparency rulesMaximum fine
€15M or 3%Reference
Art. 99(4)Breach
Incorrect or misleading information to authoritiesMaximum fine
€7.5M or 1%Reference
Art. 99(5)The higher of the two amounts applies, except for SMEs and startups, where the lower one does.
Where teams usually fall short
- No inventory of the AI systems in use and their risk level.
- Chatbots and AI features that do not tell users they are AI.
- No human oversight designed in for AI that makes or supports decisions about people.
- Training data with undocumented sources or no bias checks.
- No technical documentation or logging for systems that may be high-risk.
What the free assessment covers
The free SwaSec EU AI Act assessment asks 12 questions across 5 domains and takes about 8 minutes. It scores where you stand and ties each gap to the clause, control or article it relates to.
- AI System Classification (Art. 5-6). Risk classification of AI systems and prohibited AI practices.
- High-Risk AI Requirements (Art. 8-15). Mandatory requirements for high-risk AI systems covering risk management, data governance, documentation, transparency, human oversight, and robustness.
- Transparency for All AI (Art. 50). Transparency obligations applying to all AI systems, including chatbots and AI-generated content.
- General-Purpose AI Models (Art. 51-56). Obligations for providers and deployers of general-purpose AI models including foundation models and LLMs.
- Governance and Compliance (Art. 16-27). Quality management systems, provider obligations, and deployer obligations for high-risk AI systems.
Start the EU AI Act assessment. It is a self-assessment, not an audit or a certification.
How EU AI Act overlaps with other frameworks
EU AI Act shares 4 areas with the other frameworks SwaSec covers. Where it can, the assessment asks a shared area once, and the answer counts toward each framework.
- Risk Assessment, shared with ISO 27001, ISO 42001, SOC 2 and GDPR. Asked separately, because each framework wants something different.
- Data Governance, shared with ISO 42001 and GDPR. Asked separately, because each framework wants something different.
- Human Oversight of AI, shared with ISO 42001. Asked once.
- Transparency, shared with GDPR. Asked separately, because each framework wants something different.
Frequently asked questions
Does the EU AI Act apply to companies outside the EU?
Yes, when their AI systems are placed on the market in the EU or their output is used in the EU, wherever the company is based.
Was the EU AI Act delayed?
Only the high-risk rules. The Digital Omnibus moved them to 2 December 2027 for Annex III systems and 2 August 2028 for AI in regulated products. The bans, AI literacy, general-purpose AI rules and transparency obligations already apply.
Is my chatbot high-risk?
Usually not. Most chatbots are limited risk: you must tell people they are talking to an AI. A chatbot becomes high-risk when it is used for a high-risk purpose, such as screening job candidates.
What is the difference between a provider and a deployer?
A provider develops an AI system, or has one developed, and places it on the market under its own name. A deployer uses an AI system in a professional setting. A company can be both.
What does the free SwaSec EU AI Act assessment cover?
12 questions across 5 domains, taking about 8 minutes, with no signup. It gives you a score for EU AI Act, the gaps it found, and the clause, control or article each gap relates to.
Sources
This guide is general information, not legal advice. Last updated 1st October 2026.