← All cheat sheets

EU AI ACT

Plain-text reference · 5 KB. Read it, search it (Ctrl-F) or print it.

OVERVIEW#

The EU AI Act (Regulation (EU) 2024/1689) is the first horizontal AI
law, using a risk-based tiering. It entered into force 1 August 2024
and phases in through 2 August 2027. This sheet maps the risk tiers,
key dates, obligations, and penalties - with financial-sector context.

KEY FACTS#

# Regulation:   (EU) 2024/1689 (AI Act)
# In force:     1 August 2024
# Full roll-out: 2 August 2027
# Governance:   EU AI Office + AI Board; national competent authorities
# Scope:        providers, deployers, importers, distributors placing
#               AI on the EU market or affecting EU persons

RISK TIERS#

# 1. UNACCEPTABLE (prohibited, Art.5) - banned
# 2. HIGH-RISK (Annex III + Annex I product areas) - strict controls
# 3. LIMITED / TRANSPARENCY (Art.50) - disclosure duties
# 4. MINIMAL - no specific obligations
# + GPAI (general-purpose AI models) - separate obligations layer

TIMELINE#

# 01 Aug 2024  Entry into force
# 02 Feb 2025  Prohibited practices (Art.5) + AI literacy (Art.4) apply
# 02 Aug 2025  GPAI obligations; national authorities designated;
#              penalties framework; EU governance operational
# 02 Aug 2026  Majority of rules; HIGH-RISK (Annex III) systems apply;
#              transparency (Art.50); most fines enforceable
# 02 Aug 2027  Full application; high-risk AI embedded in regulated
#              products (Annex I); legacy GPAI full compliance

PROHIBITED PRACTICES (Art.5, since Feb 2025)#

# - Subliminal / manipulative / deceptive techniques distorting behavior
# - Exploitation of vulnerabilities (age, disability, socio-economic)
# - Social scoring by public/private actors
# - Predictive policing based purely on profiling
# - Untargeted scraping of facial images for FR databases
# - Emotion recognition in workplace / education (limited exceptions)
# - Biometric categorisation inferring sensitive attributes
# - Real-time remote biometric ID in public (law-enforcement, narrow)

HIGH-RISK OBLIGATIONS (from Aug 2026)#

# For providers of Annex III systems (e.g. credit scoring, employment,
# critical infrastructure, biometrics):
#   - Risk management system (lifecycle)
#   - Data governance / quality of training data
#   - Technical documentation + record-keeping (logging)
#   - Transparency + instructions for use
#   - Human oversight measures
#   - Accuracy, robustness, cybersecurity
#   - Conformity assessment + CE marking + EU database registration
#   - Post-market monitoring
# Deployers: ensure human oversight, monitor, keep logs; FRIA where
#   required (fundamental rights impact assessment)

GPAI OBLIGATIONS (from Aug 2025)#

# All GPAI providers: technical documentation, info to downstream
#   providers, copyright policy, training-data summary
# GPAI with SYSTEMIC RISK (high-capability): + model evaluation /
#   adversarial testing, systemic-risk assessment/mitigation,
#   serious-incident reporting, cybersecurity, energy reporting
# Code of Practice supports compliance during transition

TRANSPARENCY (Art.50, from Aug 2026)#

# - Inform users they interact with an AI system (chatbots)
# - Mark AI-generated / manipulated content (deepfakes, synthetic media)
# - Disclose emotion-recognition / biometric-categorisation use

PENALTIES#

# Prohibited practices:  up to EUR 35M or 7% global annual turnover
# Other obligations:     up to EUR 15M or 3% turnover
# Supplying incorrect info: up to EUR 7.5M or 1% turnover
# (whichever is higher; SMEs = lower of the two)

FINANCIAL-SECTOR NOTES#

# - Credit scoring / creditworthiness and life/health insurance risk
#   pricing are High-Risk (Annex III)
# - AI Act obligations layer ON TOP OF sector rules; supervisory tasks
#   can be integrated with existing financial supervision
# - Overlaps: GDPR (DPIA), DORA (ICT risk of AI systems), model risk
#   governance - run FRIA + DPIA together where both apply

EXAMPLES#

# Inventory AI systems and classify each into a risk tier
# Confirm prohibited-practice systems were discontinued (since Feb 2025)
# For a credit-scoring model: build the Art.9-15 high-risk control set
# For a customer chatbot: implement Art.50 AI-interaction disclosure
# Map AI system ICT risk to DORA; run FRIA + DPIA for high-risk use

NOTES#

- Dates are the "2 August" cadence except the 2 Feb 2025 prohibitions
- High-risk is the heavy lift and lands 2 Aug 2026 - scope now
- AI literacy (Art.4) is already a live obligation for staff using AI
- Verify Annex III classification per use case; borderline systems
  need documented justification
- This is a practitioner reference, not legal advice; confirm final
  text and any delegated acts on EUR-Lex

Defensive reference on CyberRamen. Offensive / red-team sheets live on OffensiveRamen.com.