A structured guide to classification, provider controls, deployer duties and phased high-risk application dates.
Classification first
Check Article 6 and the relevant Annex. Capture the system’s intended purpose and the reasoning behind the assessment. Seek qualified review for borderline applications.
Read the legal text ↗Provider control areas
For applicable high-risk systems, the Act sets requirements across risk management, data and data governance, documentation, record-keeping, transparency to deployers, human oversight, accuracy, robustness and cybersecurity.
- Design and test controls against the intended use
- Maintain technical documentation and logs where required
- Plan the conformity route and post-market processes
Check the applicable date
Following the 2026 AI Omnibus amendments, Annex III high-risk rules are scheduled for 2 December 2027 and Annex I product-linked high-risk rules for 2 August 2028. Other provisions may already apply.
Check the official timeline ↗This guide is an orientation, not a legal determination. Check the current legal text and official implementation guidance for your system.
Read the AI Act ↗European Commission overview ↗