Examples
Worked examples
- Is an instance
A system that infers a person's political opinions from facial images for law-enforcement profiling — an unacceptable-risk practice banned outright under Article 5.
- Is an instance
An AI tool used to screen and rank job applicants — a high-risk system under the Annex III employment category, requiring a risk-management system, data governance, technical documentation, and human oversight before deployment.
- Is an instance
A customer-support chatbot that tells the user it is an AI system — the Article 50(1) transparency obligation for a limited-risk system.
Counter-examples
Looks similar, but isn't
- Not an instance
An AI model a university lab builds, trains, and runs entirely as the instrument of a research project, with no operational deployment beyond that project — falls outside the Act's scope under the Article 2(6) research exemption, regardless of what risk tier it would otherwise sit in. The exemption is purpose-based, not technology-based, and breaks the moment the same system is deployed operationally (licensed out, adopted institution-wide, used to make a real decision about a real person outside the research protocol).
Editorial commentary
The EU AI Act (Regulation (EU) 2024/1689) is the European Union’s horizontal law governing the development, deployment, and use of artificial intelligence. It entered into force on 1 August 2024 and applies extraterritorially: it reaches any provider or deployer whose AI system’s output is used in the EU, not only EU-based organisations. Rather than regulating “AI” as a single category, it sorts every AI system into one of four risk tiers and attaches obligations that scale with the risk, and it layers a separate regime on top for general-purpose AI (GPAI) models regardless of the risk tier of any downstream application built on them.
The four risk tiers
Unacceptable risk (Article 5): practices banned outright — social scoring, subliminal or manipulative techniques causing harm, exploiting vulnerabilities, most real-time remote biometric identification in public spaces for law enforcement, untargeted scraping of facial images to build recognition databases, and emotion inference in workplaces or education (with narrow exceptions). High risk: systems that are safety components of regulated products (Annex I route) or that fall into one of eight Annex III use-case categories — biometrics, critical infrastructure, education, employment, essential services, law enforcement, migration/border control, and justice/democratic processes. These carry the heaviest obligations: risk management, data governance, technical documentation, logging, human oversight, accuracy/robustness/cybersecurity, and conformity assessment before market placement. Limited risk: transparency-only obligations under Article 50 — disclosing AI interaction, marking synthetic content, and flagging deepfakes or emotion-recognition/biometric-categorisation use. Minimal risk: everything else, with no mandatory obligations beyond voluntary codes of conduct.
General-purpose AI model obligations
GPAI providers have carried baseline duties under Article 53 since 2 August 2025: technical documentation, documentation for downstream providers, a copyright policy addressing EU text-and-data-mining opt-outs, and a publicly available summary of training content using the AI Office’s template. Models presumed to carry “systemic risk” — cumulative training compute above 10^25 FLOPs, or Commission designation — face additional duties under Article 55: model evaluation and adversarial testing, systemic-risk assessment and mitigation, serious-incident reporting, and cybersecurity safeguards. An open-source licence exempts a model from only the two documentation duties, never from the copyright-policy or training-data-summary duties, and never from the systemic-risk duties at all.
Timeline: phased application, and the 2026 Digital Omnibus
The Act applies in stages rather than all at once. Prohibited practices (Article 5) and AI-literacy obligations (Article 4) took effect 2 February 2025. GPAI obligations took effect 2 August 2025. The remaining high-risk and transparency obligations were originally due 2 August 2026 (Annex III) and 2 August 2027 (Annex I embedded products), under the general application date set by Article 113. That timeline was revised by the “Digital Omnibus on AI” (Regulation (EU) 2026/1744), published in the Official Journal 24 July 2026 and in force from 27 July 2026: standalone Annex III high-risk obligations were deferred to 2 December 2027, Annex I embedded-product high-risk obligations to 2 August 2028, and systems already on the market before 2 August 2026 got a grace period to 2 December 2026 for the Article 50(2) synthetic-content watermarking duty. The Omnibus left the Article 4/5 prohibited-practices and AI-literacy dates, the Article 51–56 GPAI regime, and the Article 2(6) research exemption unchanged. Because implementing and delegated acts for the revised timeline are still being developed, treat any specific compliance date as provisional and re-check the official AI Act Service Desk timeline before relying on it for a filing deadline.
The research exemption — and where it stops applying
This is the question a university research-administration office actually needs answered, and the Act draws the line in two separate provisions. Article 2(6) excludes “AI systems or AI models, including their output, specifically developed and put into service for the sole purpose of scientific research and development” from the Regulation entirely — a purpose-based exemption, not a technology-based one. A model built and run entirely as the object or instrument of a research project sits outside the Act regardless of what risk tier it would otherwise occupy. The exemption fails the moment the same system is also used operationally: licensed out, deployed as a production tool, or used to make a real decision about a real person outside the research protocol — at which point a fresh compliance assessment is needed, not an assumption that the research-exempt origin carries forward. Article 2(8) is a separate, broader exclusion for “any research, testing or development activity regarding AI systems or AI models prior to their being placed on the market or put into service” — covering ordinary pre-deployment R&D such as benchmarking and internal prototyping even outside Article 2(6)’s narrower “sole purpose” framing. Article 2(8) carries its own carve-out that matters for human-subjects work: testing in real-world conditions is not covered by the exclusion. A pilot deployment of an AI tool with actual students, patients, job applicants, or research subjects can trigger obligations tied to real-world testing under the Act’s regulatory-sandbox provisions (Articles 57–61), separately from whichever exemption might otherwise apply — a protocol already under IRB/REC review for human-subjects reasons is a candidate for a separate AI Act touchpoint, not an automatic pass.
For the fuller walk-through of provider-versus-deployer status, the conformity-assessment path, and what changes when a research tool crosses into operational use, see EU AI Act: Obligations and Exemptions for Research Organizations. Related provisions and bodies: Article 5 (Prohibited AI Practices), Article 53 (GPAI Model Obligations), European AI Office, Fundamental Rights Impact Assessment, AI Literacy (Article 4), and AI conformance assessment.
Machine-readable encodings
Use in your systems
<role vocab="credit"
vocab-identifier="https://casrai.org/dictionary/"
vocab-term="EU AI Act"
vocab-term-identifier="https://casrai.org/dictionary/term/eu-ai-act" />{
"@context": "https://schema.org",
"@type": "DefinedTerm",
"@id": "https://casrai.org/dictionary/term/eu-ai-act",
"name": "EU AI Act",
"identifier": "https://casrai.org/dictionary/term/eu-ai-act",
"description": "Regulation (EU) 2024/1689, the European Union's law regulating AI systems and general-purpose AI (GPAI) models placed on or used in the EU market. It classifies AI systems into four risk tiers (unacceptable, high, limited, minimal) with obligations scaling to risk, applies a separate GPAI-model regime, and phases in on a multi-year timeline set by Article 113 and later revised by the 2026 'Digital Omnibus' amendment.",
"inDefinedTermSet": "https://casrai.org/dictionary/domain/compliance-regulatory#set",
"url": "https://casrai.org/dictionary/term/eu-ai-act",
"sameAs": [],
"license": "https://creativecommons.org/licenses/by/4.0/",
"publisher": {
"@id": "https://casrai.org/#organization"
},
"author": {
"@id": "https://casrai.org/#editorial-team"
},
"datePublished": "2026-08-22T14:38:58",
"dateModified": "2026-09-04T07:25:50",
"inLanguage": "en-GB",
"isAccessibleForFree": true
}







