The EU AI Act — Regulation (EU) 2024/1689 — is the world's first comprehensive horizontal AI law. It reaches companies on an extraterritorial basis, so any AI system whose output affects a natural person in the EU is in scope regardless of where you are headquartered. By August 2 2026 every deployer of a high-risk system must produce a risk management record, a conformity assessment, human oversight, transparency notices, and post-market monitoring. Use this guide to walk the scope test, classify your AI against the five risk tiers, satisfy GPAI obligations if you fine-tune at scale, deliver the Art. 50 transparency notices, and avoid penalties up to €35M / 7% of global turnover. Start with the free AI compliance assessment, or skim a sample compliance plan first.
12 questions · 5 minutes · Instant score · No account required
The EU AI Act assigns obligations by role (provider, deployer, importer, distributor, product manufacturer) and by risk class. If you can answer yes to the three questions below with respect to a given AI system in your stack, the system is in scope and you have to determine which of the five risk tiers applies to it.
The five roles under Article 3 of Regulation (EU) 2024/1689 (the official EU AI Act text):
Use these three questions to determine whether the EU AI Act applies to a given AI system:
Is the system's output — a credit decision, a screening result, a piece of generated content, a biometric inference — consumed by a natural person located in the EU, regardless of where you as the deployer are headquartered? Pure internal analytics with no EU consumer or employee touchpoint is typically out of scope.
Yes → Proceed to Question 2 No → EU AI Act obligations do not apply to this system (verify with counsel)Do you operate the AI under your own authority, place it on the EU market, import it, distribute it, or manufacture a product with embedded AI? Buying and using a vendor's tool makes you a deployer; fine-tuning or substantially modifying a high-risk model can make you a provider too.
Yes → Proceed to Question 3 No → No role assigned; obligations may still apply if you integrate the AI downstreamArticle 5 prohibits specific practices outright. Annex III enumerates eight high-risk categories. Article 50 imposes transparency duties on AI that interacts with natural persons, generates synthetic content, performs emotion recognition, or produces deepfakes. If your AI is in any of these three categories, the EU AI Act applies to that system.
Yes → EU AI Act applies. Determine the risk tier and apply the corresponding obligations.Article 2 of the EU AI Act applies the regulation to (a) providers placing AI systems on the EU market, (b) deployers established in the EU, and (c) providers and deployers outside the EU where the AI system's output is used in the EU. Buying and using a vendor's AI tool does not shield you from the Act when the output crosses into EU territory. The test is where the output is used, not where your servers sit or where your company is incorporated. Source: Regulation (EU) 2024/1689, Article 2 — EUR-Lex.
Every in-scope AI system falls into exactly one of five tiers. The tier drives the obligations: the higher the risk, the more documentation, oversight, and operational practice the Act requires. Below is the full operational framework for each tier as it applies to SMBs.
Article 5 prohibits specific AI practices outright. These are not high-risk — they are not permitted in any context, with narrow exceptions for law enforcement in certain listed cases. Deployers cannot use these systems for any purpose; providers cannot place them on the EU market.
AI systems in the eight Annex III categories, plus AI safety components of products covered by Annex I EU harmonisation legislation (medical devices, machinery, toys, etc.). High-risk obligations become enforceable on August 2 2026 and include the full provider + deployer stack: risk management, data governance, technical documentation, conformity assessment, transparency, human oversight, accuracy/robustness/cybersecurity, post-market monitoring.
AI that interacts with natural persons, generates synthetic content, performs emotion recognition or biometric categorisation, or produces deepfakes. Article 50 imposes transparency duties: tell people they are interacting with AI, mark synthetic content in a machine-readable manner, and disclose deepfake manipulation. These obligations apply in addition to whatever other tier the system also falls into.
AI systems outside the prohibited, high-risk, transparency, and GPAI categories. The EU AI Act applies no mandatory obligations beyond voluntary best-practice codes of conduct. The vast majority of consumer-grade AI features — spam filters, content recommenders, navigation tools — sit here. Voluntary codes are encouraged; the Commission publishes model codes for self-assessment.
General-Purpose AI models — the foundation models that can be integrated into many downstream systems. A separate obligation stack applies to GPAI providers under Articles 51–55, with additional systemic-risk obligations for models trained above 10²⁵ FLOPs of compute. SMBs are unlikely to train GPAI from scratch but may inherit obligations if they fine-tune or significantly modify such models.
Article 4 applies to every provider and deployer in scope of the Act, regardless of which risk tier the system falls into. Providers and deployers must ensure, to the best of their ability, a sufficient level of AI literacy of their staff and any other person handling the operation and use of AI systems on their behalf. For SMBs this is typically documented training, role-based competency expectations, and refresher cadence.
The EU AI Act carves out a separate obligation stack for General-Purpose AI model providers under Articles 51–55. Most SMBs will be GPAI integrators, not providers — but a non-trivial fine-tuning or downstream modification can shift your role. Here is what each path looks like.
Article 53, applicable to GPAI providers regardless of systemic-risk status, requires four operational deliverables:
Article 55 imposes additional obligations on GPAI models with systemic risk — a presumption that applies to any model trained on more than 10²⁵ FLOPs of compute. Practical obligations:
Training a foundation model from scratch above the 10²⁵ FLOPs threshold is computationally infeasible for an SMB. However, fine-tuning can shift your role. If your downstream modification materially changes the model's capabilities, capabilities profile, or intended purposes, you may become a provider yourself — inheriting Article 53 obligations for the modified model. The trigger is functional, not merely technical: it is whether the modifications "materially change" the model. If you only perform light-weight customisation (prompt-tuning, retrieval-augmented generation on a closed model without retraining weights, low-rank adapters with negligible capability change), you typically remain an integrator. Source: Regulation (EU) 2024/1689, Articles 51–55 — EUR-Lex.
Article 50 imposes specific transparency duties on deployers of AI systems that interact with natural persons, generate synthetic content, perform emotion recognition, or generate deepfakes. These duties apply in addition to whatever tier the system sits in — even a limited-risk AI carries Art. 50 obligations where the listed triggers apply.
Article 50 covers four deployer-side transparency scenarios:
Article 50(1): Deployers of an AI system that interacts directly with natural persons must inform those persons that they are interacting with an AI system, unless this is obvious to a reasonably well-informed natural person having regard to the circumstances and context of use.
Deployers of an AI system that generates synthetic audio, image, video, or text content must mark that content in a machine-readable format and detectable as artificially generated or manipulated. Providers must enable this through technical solutions effective at the point of first generation.
Deployers of emotion recognition systems must inform the exposed natural persons of the operation of the system, and process the personal data in compliance with GDPR. Limited exceptions apply for law enforcement, medical, or safety purposes with appropriate safeguards.
Deployers who generate or manipulate image, audio, or video content constituting a deepfake must disclose that the content has been artificially generated or manipulated. The disclosure must be clear, prominent, and provided at the latest when the content is first presented.
Deployers of biometric categorisation systems that infer sensitive attributes (race, political opinions, religious beliefs, etc.) must inform exposed natural persons and obtain appropriate consent where required. Categorisation systems inferring sensitive attributes are generally prohibited under Article 5(1)(g) outside limited exceptions.
Provider-side obligations also apply: providers of AI systems generating synthetic content must ensure their outputs are machine-readable and detectable as artificially generated, effective at the point of first generation. Providers of general-purpose AI models must enable downstream deployers to comply with their Art. 50 duties through technical solutions.
FAQ answers below include Art. 50 specifics: jump to the FAQ → or read the full Regulation on EUR-Lex.
The EU AI Act's enforcement rolls in phases. Two phases already complete; the third — high-risk — is now live. Here are the milestones every SMB should have on its compliance calendar.
Article 5 prohibitions became enforceable. AI systems engaged in subliminal manipulation, exploitation of vulnerabilities, social scoring by public authorities, predictive policing based on profiling, untargeted facial scraping, workplace emotion recognition (with limited exceptions), and real-time remote biometric identification in publicly accessible spaces (law enforcement only) are now prohibited. Member State authorities enforce.
Articles 51–55 became enforceable for GPAI model providers placed on the EU market. Technical documentation under Annex XI, public training-data summary co-developed with the AI Office, copyright compliance policy under Article 53(1)(c), and the downstream cooperation duty are now live. Models above 10²⁵ FLOPs of compute presumed to carry systemic risk and carry the additional Article 55 obligations.
High-risk AI systems — Annex III categories and Annex I safety components — become fully enforceable. Deployers must complete and maintain their compliance record: risk management system across the lifecycle, data governance with relevant and representative datasets, technical documentation per Annex IV, conformity assessment on file, transparency notices and instructions for use, human oversight operational, appropriate accuracy/robustness/cybersecurity, and post-market monitoring. The major operational milestone for SMBs.
AI systems that are safety components of products covered by Annex I EU harmonisation legislation (e.g. medical devices, machinery, in-vitro diagnostics, toys) and were placed on the market before the relevant high-risk deadline must complete the conformity assessment and re-register. This transition rule exists to accommodate long product cycles in regulated industries — but it is not a deferral of the substance of the obligations.
Member States designate national competent authorities responsible for enforcement of the EU AI Act, and publish their penalty-design rules. Penalties are enforced at Member State level; the EU AI Act sets the upper bounds (€35M, €15M, €7.5M) and Member States determine the actual application, including any lower tiers for SMEs. Article 99 specifically caps the percentage-of-turnover amounts at the absolute euro figures for small and micro enterprises.
The five risk-tier obligation sets are reproduced below in checklist form for easy operational use. A separate print-friendly HTML version is also available for download — it strips out styling chrome and renders cleanly on letter-size paper or as a saved reference document for your compliance team.
A standalone, print-friendly version of this checklist is available at /checklists/eu-ai-act-checklist.html. It is sized for letter paper, contains no JavaScript or analytics, and is suitable for printing and including in your compliance binder or sharing with your legal team.
If your company serves EU residents or deploys AI with extraterritorial reach, the EU AI Act is independent of Colorado's SB 24-205 and SB 26-189. The trigger, scope, enforcement authority, penalty structure, and disclosure rules differ. A complete multi-jurisdiction program addresses each regime with its own evidence base.
| Dimension | EU AI Act | Colorado SB 24-205 / SB 26-189 |
|---|---|---|
| Trigger | AI system whose output is used in the EU; or provider placing AI on the EU market | AI system touching Colorado consumers in a covered context (procurement, screening, finance, healthcare, etc.) |
| Scope | Risk-tiered: prohibited / high-risk Annex III / Art. 50 transparency / GPAI / minimal risk | SB 24-205: 7 consequential-decision domains; SB 26-189: 6 covered contexts (broader) |
| Extraterritorial reach | Yes — Art. 2 covers non-EU providers and deployers where output is used in EU | Yes — applies to AI interacting with Colorado consumers regardless of company HQ |
| AI system inventory | Required for high-risk systems (Annex IV technical documentation) and database registration | SB 26-189 requires documented inventory with quarterly review |
| Impact / risk assessment | Risk management system across full lifecycle (Art. 9); not named "impact assessment" | SB 26-189 impact assessment with 9 specific elements + executive sign-off |
| Consumer disclosures | Art. 50 transparency duties; AI interaction + synthetic content + deepfake markers | SB 26-189 pre-interaction + post-decision + data category disclosures |
| Vendor management | Deployers' Art. 26 obligations on humans, input data, monitoring; provider liability under Art. 16 | SB 26-189 enumerated procurement clauses with 30-day update notice |
| Ongoing monitoring | Post-market monitoring per Art. 72 (provider); Art. 26 (deployer); serious-incident reporting | SB 26-189 quarterly inventory + annual reassessment + change-trigger rules |
| Affirmative defense | No formal affirmative defense; framework adoption supports compliance posture | SB 24-205 NIST AI RMF / ISO 42001 = rebuttable presumption of reasonable care |
| Maximum penalty | €35M / 7% (prohibited); €15M / 3% (other); €7.5M / 1% (incomplete info) | $20,000 per violation under Colorado Consumer Protection Act |
| Private right of action | Restricted; primarily Member State authority enforcement (with sector-specific carve-outs) | No — AG enforcement only |
| Best compliance posture | Run a risk-classification inventory; map each in-scope system to Article 9–15 + Art. 26 obligations; deploy Art. 50 disclosures; satisfy Art. 4 AI literacy | NIST AI RMF adoption + annual review + AG reporting on incidents |
Sources: Regulation (EU) 2024/1689 — EUR-Lex; Colorado SB 24-205; Colorado SB 26-189. If you're building a program that covers both, see our SB 26-189 deep dive and our existing EU AI Act SMB pillar.
Knowing the law is the first step. Knowing exactly which of your AI systems are in scope under the EU AI Act, which risk tier applies to each, and getting a prioritized written action plan before the August 2 2026 enforcement deadline is the second. GovernIQ automates the gap analysis — built specifically for SMBs, not enterprise GRC teams.
Covers AI tool inventory, data handling practices, employee training status, policy governance, vendor management, and monitoring posture. Takes 5 minutes. Generates a 0–100 compliance score and identifies up to 8 specific policy gaps — mapped to the EU AI Act risk tiers and the August 2 2026 high-risk deadline.
Take the Assessment →See a real example of the personalized Compliance Action Plan output for a fictional financial advisory firm facing similar EU AI Act risk-classification and conformity-assessment obligations. Understand what you'll get before you purchase.
View Sample Plan →After a $299 one-time purchase, receive a full Compliance Action Plan specific to your company's AI stack, EU AI Act risk classification, SB 26-189 / SB 24-205 gaps, risk level, and industry — with actionable items, risk management templates, Art. 50 disclosure language, vendor contract clause library, monitoring cadence, and an August 2 2026 remediation roadmap.
See Pricing →The GovernIQ assessment maps each of your AI systems to the EU AI Act risk tiers, checks Article 4 AI literacy, Article 50 transparency readiness, and the high-risk operational framework, and tells you exactly what to fix before enforcement begins. Free. No account required.
Free assessment · Personalized Compliance Action Plan $299 · No subscription