EU AI ACT
OVERVIEW#
The EU AI Act (Regulation (EU) 2024/1689) is the first horizontal AI law, using a risk-based tiering. It entered into force 1 August 2024 and phases in through 2 August 2027. This sheet maps the risk tiers, key dates, obligations, and penalties - with financial-sector context.
KEY FACTS#
# Regulation: (EU) 2024/1689 (AI Act) # In force: 1 August 2024 # Full roll-out: 2 August 2027 # Governance: EU AI Office + AI Board; national competent authorities # Scope: providers, deployers, importers, distributors placing # AI on the EU market or affecting EU persons
RISK TIERS#
# 1. UNACCEPTABLE (prohibited, Art.5) - banned # 2. HIGH-RISK (Annex III + Annex I product areas) - strict controls # 3. LIMITED / TRANSPARENCY (Art.50) - disclosure duties # 4. MINIMAL - no specific obligations # + GPAI (general-purpose AI models) - separate obligations layer
TIMELINE#
# 01 Aug 2024 Entry into force # 02 Feb 2025 Prohibited practices (Art.5) + AI literacy (Art.4) apply # 02 Aug 2025 GPAI obligations; national authorities designated; # penalties framework; EU governance operational # 02 Aug 2026 Majority of rules; HIGH-RISK (Annex III) systems apply; # transparency (Art.50); most fines enforceable # 02 Aug 2027 Full application; high-risk AI embedded in regulated # products (Annex I); legacy GPAI full compliance
PROHIBITED PRACTICES (Art.5, since Feb 2025)#
# - Subliminal / manipulative / deceptive techniques distorting behavior # - Exploitation of vulnerabilities (age, disability, socio-economic) # - Social scoring by public/private actors # - Predictive policing based purely on profiling # - Untargeted scraping of facial images for FR databases # - Emotion recognition in workplace / education (limited exceptions) # - Biometric categorisation inferring sensitive attributes # - Real-time remote biometric ID in public (law-enforcement, narrow)
HIGH-RISK OBLIGATIONS (from Aug 2026)#
# For providers of Annex III systems (e.g. credit scoring, employment, # critical infrastructure, biometrics): # - Risk management system (lifecycle) # - Data governance / quality of training data # - Technical documentation + record-keeping (logging) # - Transparency + instructions for use # - Human oversight measures # - Accuracy, robustness, cybersecurity # - Conformity assessment + CE marking + EU database registration # - Post-market monitoring # Deployers: ensure human oversight, monitor, keep logs; FRIA where # required (fundamental rights impact assessment)
GPAI OBLIGATIONS (from Aug 2025)#
# All GPAI providers: technical documentation, info to downstream # providers, copyright policy, training-data summary # GPAI with SYSTEMIC RISK (high-capability): + model evaluation / # adversarial testing, systemic-risk assessment/mitigation, # serious-incident reporting, cybersecurity, energy reporting # Code of Practice supports compliance during transition
TRANSPARENCY (Art.50, from Aug 2026)#
# - Inform users they interact with an AI system (chatbots) # - Mark AI-generated / manipulated content (deepfakes, synthetic media) # - Disclose emotion-recognition / biometric-categorisation use
PENALTIES#
# Prohibited practices: up to EUR 35M or 7% global annual turnover # Other obligations: up to EUR 15M or 3% turnover # Supplying incorrect info: up to EUR 7.5M or 1% turnover # (whichever is higher; SMEs = lower of the two)
FINANCIAL-SECTOR NOTES#
# - Credit scoring / creditworthiness and life/health insurance risk # pricing are High-Risk (Annex III) # - AI Act obligations layer ON TOP OF sector rules; supervisory tasks # can be integrated with existing financial supervision # - Overlaps: GDPR (DPIA), DORA (ICT risk of AI systems), model risk # governance - run FRIA + DPIA together where both apply
EXAMPLES#
# Inventory AI systems and classify each into a risk tier # Confirm prohibited-practice systems were discontinued (since Feb 2025) # For a credit-scoring model: build the Art.9-15 high-risk control set # For a customer chatbot: implement Art.50 AI-interaction disclosure # Map AI system ICT risk to DORA; run FRIA + DPIA for high-risk use
NOTES#
- Dates are the "2 August" cadence except the 2 Feb 2025 prohibitions - High-risk is the heavy lift and lands 2 Aug 2026 - scope now - AI literacy (Art.4) is already a live obligation for staff using AI - Verify Annex III classification per use case; borderline systems need documented justification - This is a practitioner reference, not legal advice; confirm final text and any delegated acts on EUR-Lex
EU AI ACT CHEATSHEET ==================== Source: https://cheatsheet.johlem.net OVERVIEW -------- The EU AI Act (Regulation (EU) 2024/1689) is the first horizontal AI law, using a risk-based tiering. It entered into force 1 August 2024 and phases in through 2 August 2027. This sheet maps the risk tiers, key dates, obligations, and penalties - with financial-sector context. KEY FACTS --------- # Regulation: (EU) 2024/1689 (AI Act) # In force: 1 August 2024 # Full roll-out: 2 August 2027 # Governance: EU AI Office + AI Board; national competent authorities # Scope: providers, deployers, importers, distributors placing # AI on the EU market or affecting EU persons RISK TIERS ---------- # 1. UNACCEPTABLE (prohibited, Art.5) - banned # 2. HIGH-RISK (Annex III + Annex I product areas) - strict controls # 3. LIMITED / TRANSPARENCY (Art.50) - disclosure duties # 4. MINIMAL - no specific obligations # + GPAI (general-purpose AI models) - separate obligations layer TIMELINE -------- # 01 Aug 2024 Entry into force # 02 Feb 2025 Prohibited practices (Art.5) + AI literacy (Art.4) apply # 02 Aug 2025 GPAI obligations; national authorities designated; # penalties framework; EU governance operational # 02 Aug 2026 Majority of rules; HIGH-RISK (Annex III) systems apply; # transparency (Art.50); most fines enforceable # 02 Aug 2027 Full application; high-risk AI embedded in regulated # products (Annex I); legacy GPAI full compliance PROHIBITED PRACTICES (Art.5, since Feb 2025) -------------------------------------------- # - Subliminal / manipulative / deceptive techniques distorting behavior # - Exploitation of vulnerabilities (age, disability, socio-economic) # - Social scoring by public/private actors # - Predictive policing based purely on profiling # - Untargeted scraping of facial images for FR databases # - Emotion recognition in workplace / education (limited exceptions) # - Biometric categorisation inferring sensitive attributes # - Real-time remote biometric ID in public (law-enforcement, narrow) HIGH-RISK OBLIGATIONS (from Aug 2026) ------------------------------------- # For providers of Annex III systems (e.g. credit scoring, employment, # critical infrastructure, biometrics): # - Risk management system (lifecycle) # - Data governance / quality of training data # - Technical documentation + record-keeping (logging) # - Transparency + instructions for use # - Human oversight measures # - Accuracy, robustness, cybersecurity # - Conformity assessment + CE marking + EU database registration # - Post-market monitoring # Deployers: ensure human oversight, monitor, keep logs; FRIA where # required (fundamental rights impact assessment) GPAI OBLIGATIONS (from Aug 2025) -------------------------------- # All GPAI providers: technical documentation, info to downstream # providers, copyright policy, training-data summary # GPAI with SYSTEMIC RISK (high-capability): + model evaluation / # adversarial testing, systemic-risk assessment/mitigation, # serious-incident reporting, cybersecurity, energy reporting # Code of Practice supports compliance during transition TRANSPARENCY (Art.50, from Aug 2026) ------------------------------------ # - Inform users they interact with an AI system (chatbots) # - Mark AI-generated / manipulated content (deepfakes, synthetic media) # - Disclose emotion-recognition / biometric-categorisation use PENALTIES --------- # Prohibited practices: up to EUR 35M or 7% global annual turnover # Other obligations: up to EUR 15M or 3% turnover # Supplying incorrect info: up to EUR 7.5M or 1% turnover # (whichever is higher; SMEs = lower of the two) FINANCIAL-SECTOR NOTES ---------------------- # - Credit scoring / creditworthiness and life/health insurance risk # pricing are High-Risk (Annex III) # - AI Act obligations layer ON TOP OF sector rules; supervisory tasks # can be integrated with existing financial supervision # - Overlaps: GDPR (DPIA), DORA (ICT risk of AI systems), model risk # governance - run FRIA + DPIA together where both apply EXAMPLES -------- # Inventory AI systems and classify each into a risk tier # Confirm prohibited-practice systems were discontinued (since Feb 2025) # For a credit-scoring model: build the Art.9-15 high-risk control set # For a customer chatbot: implement Art.50 AI-interaction disclosure # Map AI system ICT risk to DORA; run FRIA + DPIA for high-risk use NOTES ----- - Dates are the "2 August" cadence except the 2 Feb 2025 prohibitions - High-risk is the heavy lift and lands 2 Aug 2026 - scope now - AI literacy (Art.4) is already a live obligation for staff using AI - Verify Annex III classification per use case; borderline systems need documented justification - This is a practitioner reference, not legal advice; confirm final text and any delegated acts on EUR-Lex
Defensive reference on CyberRamen. Offensive / red-team sheets live on OffensiveRamen.com.