AI Act
Guide
EU Reg. 2024/1689
The AI Act, explained without the jargon.
Understand whether it applies to you, what obligations you have and by when - in plain language, no legalese.

What the AI Act is
The AI Act (EU Reg. 2024/1689) is Europe’s first law on artificial intelligence. It regulates AI systems based on risk: the more a system affects people and decisions, the more obligations it carries. It also applies to companies that use AI in their work, not just those who build it.
Who is in scope
You don’t need to build AI to have obligations: using it is enough. If your company uses an AI system for work, even just to screen CVs or assess cases, you’re a “deployer”: the AI Act asks you to know which AI systems you use, how risky they are and how you keep them under control.
- Deployer: Companies that use AI systems in their work. The most common case for an SME.
- Provider: Those who develop or place AI systems on the market. Broader obligations, especially for high risk.
The risk levels
The AI Act classifies AI uses by risk: obligations follow from there.
- Unacceptable: Uses banned across the EU, such as “social scoring” or manipulating people.
- High: AI weighing on important decisions — hiring, credit, safety. Obligations are stricter here.
- Limited: Chatbots and AI-generated content: people must know when they’re talking to an AI or seeing artificial content.
- Minimal: Almost all everyday uses: no specific obligations, beyond supporting staff AI literacy.
The deadlines
The AI Act applies in stages between 2025 and 2028.
- Feb 2025: Bans on unacceptable-risk uses, plus AI literacy.
- Aug 2026: Transparency duties: chatbots and AI-generated content.
- Dec 2027: High-risk obligations: hiring, credit, education.
- Aug 2028: Obligations for high-risk AI in already-regulated products, such as machinery.
Sources: Reg. (EU) 2024/1689 (AI Act) and 2026/1744.