Regulation (EU) 2024/1689 — in force since 1 August 2024

Are you ready for the EU AI Act?

AIActCheck classifies your AI systems against the four risk categories of the AI Act, scores your compliance maturity and returns in minutes the mandatory obligations and the actionable recommendations you need to implement to be compliant.

Start for free Learn more

What is the EU AI Act

The Regulation (EU) 2024/1689 — known as the AI Act — is the world's first horizontal regulation on artificial intelligence. It applies to those who develop (providers), use professionally (deployers), import or distribute AI systems whose output is used in the EU, regardless of where the provider is established.

Risk-based approach

Obligations are proportionate to the system's risk level: the higher the risk to rights, health or safety, the stricter the requirements.

Application timeline

2 Feb 2025: prohibited practices · 2 Aug 2025: GPAI · 2 Aug 2026: high-risk (Annex III) · 2 Aug 2027: high-risk (Annex I).

Extraterritorial scope

Even non-EU providers must comply if the system's outputs are used in the Union. No geographic "safe harbour".

National enforcement + AI Office

Each Member State designates its competent authorities. The European AI Office oversees GPAI models and coordinates cross-border supervision.

The 4 + 1 risk classes

Each AI system is classified into a single risk category. GPAI models have a dedicated discipline.

Prohibited

AI practice prohibited under Art. 5. The system cannot be placed on the EU market.

High Risk

High-risk AI system (Annex III or Annex I product safety component). Subject to strict obligations.

Limited Risk

System with transparency obligations (Art. 50): chatbots, emotion recognition, deepfakes, generated content.

Minimal Risk

No specific AI Act obligations beyond voluntary codes of conduct.

GPAI Model

General-Purpose AI model (Chapter V). Specific obligations for providers; +systemic risk if applicable.

Sanctions (Art. 99)

Higher than GDPR fines. National authorities also weigh company size, severity and duration of the infringement.

Violation of prohibited practices (Art. 5)
€ 35,000,000
or 7% of annual worldwide turnover (the higher)
Non-compliance with other obligations
€ 15,000,000
or 3% of annual worldwide turnover (the higher)
Incorrect information to authorities
€ 7,500,000
or 1% of annual worldwide turnover (the higher)

Lower caps apply to SMEs and start-ups (the lower of amount or percentage). Sanctions add to GDPR consequences when the systems process personal data.

How AIActCheck works

Three steps per project. No document upload, no AI judging your AI: just deterministic logic based on the text of the Regulation.

1

Register the project

Give your AI system a name and briefly describe what it does. Everything stays in your account.

2

Answer the questionnaire

~30-40 questions grouped by sections (scope, prohibited practices, high-risk, GPAI, transparency, maturity), with some conditional follow-ups. Average time: 7–12 minutes.

3

Get the report

Risk class, maturity score, mandatory obligations with reference to the Regulation's articles, and practical recommendations to close the gaps.

Sign in

Enter email and password to continue

Forgot password?