European Union · law

European Union Artificial Intelligence Act

Risk-based EU framework governing AI systems and general-purpose AI, with phased obligations for providers, deployers and other actors.

enforceableEuropean Union / European Commission AI OfficeVerified 23 Aug 2026

Applicability

Applies according to the AI Act's territorial, actor and system scope. Organisations should determine role, system classification and applicable transition dates for each use case.

Enforcement context

Enforced through national competent authorities and the European Commission AI Office within their respective competences.

Penalty context: Administrative fines can apply for infringements; exact exposure depends on the violated provision and organisation context. Verify against the Act and current Commission guidance.

Regulatory timeline

Material dates and status changes.

02 Aug 2026

EU AI Act

Risk-based EU framework governing AI systems and general-purpose AI, with phased obligations for providers, deployers and other actors.

Source for this event →

02 Aug 2026

Commission enforcement and Article 50 transparency obligations begin

The European Commission AI Office and national authorities begin enforcing applicable AI Act rules; Article 50 transparency obligations also apply from this date.

Source for this event →

CRG implementation mapping

Operational obligations and evidence expectations.

EU-HUMAN

Human oversight for high-impact use

Design human oversight appropriate to the system's intended use, foreseeable misuse and consequence severity.

Actor: providers/deployers · Domain: human oversight

Evidence: Oversight procedures, intervention authority, training and logs.

EU-LOG

Logging and traceability

Maintain technical and operational records needed to reconstruct material AI behaviour and decisions where applicable.

Actor: providers/deployers · Domain: traceability

Evidence: System logs, version history, event records and retention schedule.

EU-RISK

AI system risk classification

Classify relevant AI systems against prohibited, high-risk, transparency and other applicable categories.

Actor: providers/deployers · Domain: risk classification

Evidence: Documented classification rationale and periodic reassessment.

EU-ROLE

Accountability and role determination

Determine and document the organisation's role for each AI system and model before assigning controls.

Actor: providers/deployers/importers/distributors · Domain: governance

Evidence: Role register, system inventory, contracts and responsibility matrix.

EU-TRANS

Transparency to affected users

Provide required disclosures when people interact with AI or encounter certain AI-generated/manipulated content.

Actor: providers/deployers · Domain: transparency

Evidence: Disclosure designs, machine-readable marking where applicable, content labelling evidence.

Primary source

Verify the underlying instrument.

Cybatar's mapping is designed for AI governance and assurance work. Legal interpretation remains anchored to the current primary text and competent authority guidance.

Open European Commission source