1.Prohibited Practices (Art. 5)
Article 5 prohibitions have been enforceable since February 2 2025. AI systems engaging in any of the following practices must not be deployed. Verify absence, not presence — if any deployer system matches, sunset it.
- No subliminal manipulation or deceptive techniques causing harm (Art. 5(1)(a))
- No exploitation of vulnerabilities due to age, disability, or social/economic situation (Art. 5(1)(b))
- No social scoring by or for public authorities (Art. 5(1)(c))
- No predictive policing assessing individuals solely on profiling or personal characteristics (Art. 5(1)(d))
- No untargeted scraping of facial images to build recognition databases (Art. 5(1)(e))
- No emotion recognition in workplace or education contexts (with limited exceptions) (Art. 5(1)(f))
- No biometric categorisation inferring sensitive attributes (race, religion, etc.) (Art. 5(1)(g))
- No real-time remote biometric identification in publicly accessible spaces (law enforcement only) (Art. 5(1)(h))
2.High-Risk Annex III + Annex I
High-risk obligations become enforceable August 2 2026. For every Annex III or Annex I high-risk AI system in your stack, the full provider + deployer framework applies. This is the largest operational lift on the calendar.
- Risk management system across the full lifecycle (Art. 9)
- Data governance: relevant and sufficiently representative datasets (Art. 10)
- Technical documentation per Annex IV (Art. 11)
- Event logging capabilities throughout operation (Art. 12)
- Transparency to deployers: instructions for use (Art. 13)
- Human oversight measures designed for effective operation (Art. 14)
- Accuracy, robustness, cybersecurity appropriate to intended purpose (Art. 15)
- Conformity assessment completed and CE marking affixed
- EU database registration (Art. 49 / Art. 71)
- Quality management system in place (Art. 17)
- Post-market monitoring system per Art. 72 live
- Serious-incident reporting procedure documented
3.Limited Risk / Art. 50 Transparency
Article 50 transparency duties apply when the AI interacts with natural persons, generates synthetic content, performs emotion recognition or biometric categorisation, or generates deepfakes. Independent of the risk tier — these obligations apply in addition to whatever else applies.
- AI-interaction disclosure to natural persons at first interaction (Art. 50(1))
- Plain-language disclosure, not buried in a privacy policy
- Synthetic content marked in machine-readable format detectable as AI-generated (Art. 50(4))
- Emotion recognition exposed-person notice (Art. 50(3))
- Biometric categorisation notice (Art. 50(3))
- Deepfake disclosure at first presentation (Art. 50(4))
- Providers enable technical watermarking at generation time
- Disclosure lang reviewed by counsel, version-controlled
4.Minimal Risk
AI systems outside the prohibited, high-risk, transparency, and GPAI categories. No mandatory obligations beyond Article 4 AI literacy — but voluntary best-practice codes are encouraged.
- Confirm no Article 5 prohibited practices present
- Confirm system is not in any Annex III or Annex I category
- Confirm no Art. 50 transparency trigger met
- Confirm no GPAI provider or downstream-modifier responsibility
- Document the AI use and the rationale for the chosen tier
- Article 4 AI literacy training still applies to operating staff
- Voluntary best-practice codes of conduct adopted where useful
- Re-evaluate classification if the use case shifts significantly
5.GPAI Model Obligations (Art. 51–55)
Articles 51–55 apply to GPAI model providers. SMBs rarely train GPAI from scratch above the 10²⁵ FLOPs systemic-risk threshold — but fine-tuning or materially modifying a GPAI model can shift your role to provider. The functional trigger is whether the modification materially changes the model's capability profile.
- Determine whether your role is provider, deployer, or integrator
- Technical documentation per Annex XI (Art. 53(1)(a))
- Public training-data summary per Annex XI (Art. 53(1)(b))
- Copyright compliance policy under Art. 53(1)(c)
- Respect Directive (EU) 2019/790 Art. 4(3) opt-outs
- Downstream cooperation duty with GPAI integrators
- Determine whether model crosses 10²⁵ FLOPs systemic-risk threshold
- If systemic: state-of-the-art model evaluation and adversarial testing
- If systemic: serious-incident reporting to the AI Office
- If systemic: cybersecurity protection for model + infrastructure
- If systemic: energy-efficiency reporting methodology